Skip to content

Commit

Permalink
feature(k8s): add default events to k8s policies
Browse files Browse the repository at this point in the history
  • Loading branch information
josedonizetti committed Jul 19, 2023
1 parent eb4c02d commit 34c2935
Show file tree
Hide file tree
Showing 2 changed files with 93 additions and 1 deletion.
46 changes: 46 additions & 0 deletions deploy/helm/tracee/templates/tracee-policies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,52 @@ metadata:
labels:
{{- include "tracee.labels" . | nindent 4 }}
data:
default_events.yaml: |-
name: default_events
description: tracee default events
scope:
- global
rules:
- event: creat
- event: chmod
- event: fchmod
- event: chown
- event: fchown
- event: lchown
- event: ptrace
- event: setuid
- event: setgid
- event: setpgid
- event: setsid
- event: setreuid
- event: setregid
- event: setresuid
- event: setresgid
- event: setfsuid
- event: setfsgid
- event: init_module
- event: fchownat
- event: fchmodat
- event: setns
- event: process_vm_readv
- event: process_vm_writev
- event: finit_module
- event: memfd_create
- event: move_mount
- event: sched_process_exec
- event: security_inode_unlink
- event: security_socket_connect
- event: security_socket_accept
- event: security_socket_bind
- event: security_sb_mount
- event: container_create
- event: container_remove
- event: net_packet_icmp
- event: net_packet_icmpv6
- event: net_packet_dns_request
- event: net_packet_dns_response
- event: net_packet_http_request
- event: net_packet_http_response
signatures.yaml: |-
name: signature_events
description: traces all signature events
Expand Down
48 changes: 47 additions & 1 deletion deploy/kubernetes/tracee/tracee.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,55 @@ metadata:
app.kubernetes.io/part-of: tracee
name: tracee-policies
data:
default_events.yaml: |-
name: default_events
description: tracee default events
scope:
- global
rules:
- event: creat
- event: chmod
- event: fchmod
- event: chown
- event: fchown
- event: lchown
- event: ptrace
- event: setuid
- event: setgid
- event: setpgid
- event: setsid
- event: setreuid
- event: setregid
- event: setresuid
- event: setresgid
- event: setfsuid
- event: setfsgid
- event: init_module
- event: fchownat
- event: fchmodat
- event: setns
- event: process_vm_readv
- event: process_vm_writev
- event: finit_module
- event: memfd_create
- event: move_mount
- event: sched_process_exec
- event: security_inode_unlink
- event: security_socket_connect
- event: security_socket_accept
- event: security_socket_bind
- event: security_sb_mount
- event: container_create
- event: container_remove
- event: net_packet_icmp
- event: net_packet_icmpv6
- event: net_packet_dns_request
- event: net_packet_dns_response
- event: net_packet_http_request
- event: net_packet_http_response
signatures.yaml: |-
name: signature_events
description: traces all signature events
description: tracee default signature events
scope:
- global
rules:
Expand Down

0 comments on commit 34c2935

Please sign in to comment.