falco: add rules for git hook tampering and unexpected pack-service children
Written after the 2026-08-10/11 gitea internal-API log-poisoning attack that planted a malicious uploadpack.packObjectsHook backdoor. Catches both the planting (unexpected exec from a hooks/ path) and the firing (git-upload-pack/git-receive-pack spawning anything but its own pack-objects binary), independent of how the hook config got written.
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
# Custom rule: catch execution of any git hook file gitea didn't put there.
|
||||
# Added after the 2026-08-10/11 gitea internal-API log-poisoning attack, where
|
||||
# an attacker used /api/internal/manager/add-logger to write a malicious
|
||||
# uploadpack.packObjectsHook entry into the global .gitconfig, pointed at a
|
||||
# planted hooks/pre-applypatch.sample file under an unrelated repo. Gitea only
|
||||
# ever manages four hook names per repo (post-receive, pre-receive, update,
|
||||
# proc-receive), each delegating to a same-named script under hooks/*.d/gitea -
|
||||
# anything else executing from a hooks/ path is not something Gitea put there.
|
||||
|
||||
- list: gitea_managed_hook_names
|
||||
items: [post-receive, pre-receive, update, proc-receive, gitea]
|
||||
|
||||
- rule: Unexpected git hook execution
|
||||
desc: >
|
||||
A process executed from a path under a git repository's hooks/ directory
|
||||
whose name isn't one of Gitea's own managed hook scripts. Catches planted
|
||||
hooks used for persistence/RCE (e.g. a malicious uploadpack.packObjectsHook
|
||||
or receive hook), independent of how the file got written.
|
||||
condition: >
|
||||
spawned_process
|
||||
and container.name = "gitea"
|
||||
and proc.exepath contains "/hooks/"
|
||||
and not proc.name in (gitea_managed_hook_names)
|
||||
output: >
|
||||
Unexpected git hook executed
|
||||
(user=%user.name command=%proc.cmdline exepath=%proc.exepath
|
||||
parent=%proc.pname container=%container.name pid=%proc.pid)
|
||||
priority: CRITICAL
|
||||
tags: [git, persistence, mitre_persistence]
|
||||
Reference in New Issue
Block a user