Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Update fbash rules to use proc.sname.
Update fbash rules to use proc.sname instead of proc.aname and to rely on sessions instead of process ancestors. I also wanted to add details on the address/port being listened to but that's blocked on falcosecurity/falco#86. Along with this change, there are new positive trace files installer-bash-starts-network-server.scap and installer-bash-starts-session.scap that test these updated rules.
- Loading branch information