falco: add rules for git hook tampering and unexpected pack-service children
Written after the 2026-08-10/11 gitea internal-API log-poisoning attack that planted a malicious uploadpack.packObjectsHook backdoor. Catches both the planting (unexpected exec from a hooks/ path) and the firing (git-upload-pack/git-receive-pack spawning anything but its own pack-objects binary), independent of how the hook config got written.
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
# Custom rule: catch git-upload-pack/git-receive-pack forking anything other
|
||||
# than git's own pack-objects binary. Added after the 2026-08-10/11 gitea
|
||||
# log-poisoning attack, which planted a malicious `uploadpack.packObjectsHook`
|
||||
# global git config entry - a documented git RCE primitive where upload-pack
|
||||
# forks an attacker-chosen executable instead of git-pack-objects on every
|
||||
# fetch/clone. This is the moment the backdoor actually fires, independent of
|
||||
# how the hook config got planted, so it's a strong last-line catch even if
|
||||
# git-hook-tamper.yaml's file-write detection is bypassed some other way.
|
||||
|
||||
- list: git_pack_children
|
||||
items: [git-pack-objects, git, git-remote-https, git-remote-http]
|
||||
|
||||
- rule: Unexpected child process of git pack service
|
||||
desc: >
|
||||
git-upload-pack or git-receive-pack spawned a process that isn't git's own
|
||||
pack-objects binary. Normal fetch/push never does this - it's the exact
|
||||
behavior of an abused uploadpack.packObjectsHook / pre-receive-style RCE.
|
||||
condition: >
|
||||
spawned_process
|
||||
and container.name = "gitea"
|
||||
and proc.pname in (git-upload-pack, git-receive-pack)
|
||||
and not proc.name in (git_pack_children)
|
||||
output: >
|
||||
git pack service spawned unexpected child process
|
||||
(user=%user.name command=%proc.cmdline parent=%proc.pname
|
||||
container=%container.name pid=%proc.pid)
|
||||
priority: CRITICAL
|
||||
tags: [git, execution, mitre_execution]
|
||||
Reference in New Issue
Block a user