diff --git a/falco/rules/tune-noise.yaml b/falco/rules/tune-noise.yaml index 7770a31..dafb2ce 100644 --- a/falco/rules/tune-noise.yaml +++ b/falco/rules/tune-noise.yaml @@ -49,3 +49,20 @@ (container.image.repository = "docker.gitea.com/gitea" and proc.name = gitea) or (container.image.repository = "lscr.io/linuxserver/obsidian") or (container.image.repository = "tsl0922/ttyd" and proc.name in (telnet, pv, busybox-extras)) + +# "Redirect STDOUT/STDIN to Network Connection in Container" false-positives, +# both confirmed recurring (not one-off) via netdata's alert history: +# - gitea: sshd/sshd-session redirect the just-accepted SSH connection's +# socket onto stdin/stdout/stderr via dup2 - this is simply how every SSH +# server handles every session, not a reverse shell. Fires 4x per SSH +# connection (sshd x2, sshd-session x2). Scoped to those two binaries in +# this one container, not the whole image, since gitea itself spawning +# this pattern from some other binary would still be worth flagging. +# - fireflyiii/core: its wait-for-it.sh startup script opens a raw TCP +# connection to the postgres container to poll for DB readiness, which +# redirects stdio the same way a reverse shell would mechanically. Scoped +# to the script's own cmdline, not the whole image. +- macro: user_known_stand_streams_redirect_activities + condition: > + (container.image.repository = "docker.gitea.com/gitea" and proc.name in (sshd, sshd-session)) + or (container.image.repository = "fireflyiii/core" and proc.cmdline contains "wait-for-it.sh")