From 5857874e95f78260b2b589a02379a1fd1a81da60 Mon Sep 17 00:00:00 2001 From: incertum Date: Mon, 3 Apr 2023 11:17:38 -0700 Subject: [PATCH] new(rules): comment out new umount macro keep in rules as hint for end users Co-authored-by: Jason Dellaluce Co-authored-by: Andrea Terzolo Signed-off-by: incertum --- rules/falco_rules.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index 6ebcc51d..5a436b33 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -76,8 +76,8 @@ # %evt.arg.flags available for evt.dir=>, but only for umount2 # %evt.arg.name is path and available for evt.dir=< -- macro: umount - condition: (evt.type in (umount, umount2)) +# - macro: umount +# condition: (evt.type in (umount, umount2)) - macro: spawned_process condition: (evt.type in (execve, execveat) and evt.dir=<)