From 283a62f464bbd9b35cb2fb3a7368720151b2aafc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tr=E1=BA=A7n=20=C4=90=E1=BB=A9c=20Ph=C3=BA?= <30786617+Phu96@users.noreply.github.com> Date: Thu, 10 Oct 2024 17:28:37 +0700 Subject: [PATCH] fix: fix typo safe_etc_dirs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Trần Đức Phú <30786617+Phu96@users.noreply.github.com> --- rules/falco-sandbox_rules.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/falco-sandbox_rules.yaml b/rules/falco-sandbox_rules.yaml index 6dbc3129..8af3ac72 100644 --- a/rules/falco-sandbox_rules.yaml +++ b/rules/falco-sandbox_rules.yaml @@ -686,7 +686,7 @@ tags: [maturity_sandbox, host, container, filesystem, mitre_persistence, T1543] - list: safe_etc_dirs - items: [/etc/cassandra, /etc/ssl/certs/java, /etc/logstash, /etc/nginx/conf.d, /etc/container_environment, /etc/hrmconfig, /etc/fluent/configs.d. /etc/alertmanager] + items: [/etc/cassandra, /etc/ssl/certs/java, /etc/logstash, /etc/nginx/conf.d, /etc/container_environment, /etc/hrmconfig, /etc/fluent/configs.d, /etc/alertmanager] - macro: fluentd_writing_conf_files condition: (proc.name=start-fluentd and fd.name in (/etc/fluent/fluent.conf, /etc/td-agent/td-agent.conf))