Skip to content

Commit 3ed5856

Browse files
authored
Update process exclusions in TOML file
1 parent d8bd5cf commit 3ed5856

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

rules/linux/persistence_shared_object_creation.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -170,10 +170,10 @@ file.path:(
170170
process.name:(
171171
"dockerd" or "dpkg" or "rpm" or "snapd" or "yum" or "vmis-launcher" or "pacman" or "apt-get" or "dnf" or "podman" or
172172
platform-python* or "dnf-automatic" or "unattended-upgrade" or "apk" or "snap-update-ns" or "install" or "exe" or
173-
"systemd" or "root" or "sshd" or "pip" or "jlink" or python* or "update-alternatives" or pip* or "crio" or
174-
"ssm-agent-worker" or "packagekitd"
173+
"systemd" or "root" or "sshd" or "pip" or "jlink" or python* or "update-alternatives" or pip* or "crio" or "packagekitd"
175174
) or
176175
(process.name:"vmware-install.pl" and file.path:/usr/lib/vmware-tools/*) or
176+
(process.name:"ssm-agent-worker" and file.path:/usr/lib/jvm/java*) or
177177
process.executable : (/dev/fd/* or "/" or "/kaniko/executor" or "/usr/bin/buildah")
178178
)
179179
'''

0 commit comments

Comments
 (0)