Skip to content

[Suite] Add ptrace-based Falco rules support #289

@ekoops

Description

@ekoops

Motivation

User needs support for testing Falco rules involving the ptrace system call.

Feature

Supporting a ptrace system call test step for a limited number of operations will be a good starting point, but some ptrace operations require

  1. the tracee process to be stopped under some specific conditions (i.e after performing actions like trying to execute a system call
  2. the tracer to wait on the tracee process and evaluate the returned status
  3. the tracer to run the desired operation (e.g.: PTRACE_PEEKUSER et simila)

Given this, maybe it is worth to implement a ptrace resource, allowing to request these complex flows automatically.

Alternatives

Additional context

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions