generated from falcosecurity/template-repository
-
Notifications
You must be signed in to change notification settings - Fork 42
Open
Labels
Description
Motivation
User needs support for testing Falco rules involving the ptrace system call.
Feature
Supporting a ptrace system call test step for a limited number of operations will be a good starting point, but some ptrace operations require
- the tracee process to be stopped under some specific conditions (i.e after performing actions like trying to execute a system call
- the tracer to wait on the tracee process and evaluate the returned status
- the tracer to run the desired operation (e.g.:
PTRACE_PEEKUSERet simila)
Given this, maybe it is worth to implement a ptrace resource, allowing to request these complex flows automatically.
Alternatives
Additional context
Reactions are currently unavailable