falco: [UMBRELLA] Missing syscalls

Motivation

I think we need an issue to track all the missing syscalls that can have a security value for Falco. I detected these ones right now:

Please if you have in mind other syscalls, leave a comment under this issue and I will add them to the list. This issue could also be a point of reference for discussing which syscalls may be more relevant and therefore have a higher priority. I hope it could be helpful for all the Falco community πŸ˜ƒ

About this issue

  • Original URL
  • State: open
  • Created 2 years ago
  • Reactions: 5
  • Comments: 16 (12 by maintainers)

Commits related to this issue

Most upvoted comments

falcosecurity/libs#649 adds support for all the listed syscalls, as generic events.

Hi @Andreagit97, it seems to me that we are missing monitoring for the prctl syscall. I think it could be useful to add monitoring for it since it can be used to e.g. change a process name, paired with a subsequent fork! If you agree, let’s add it to the list!

Completely agree with you @loresuso we need it! I wll add it to the list, thank you!

Ref: https://github.com/blackberry/Falco-bypasses/blob/main/fubers/fuber-fakeparents.c#L29