Logo
Explore Help
Sign In
homelab/docker-infrastructure
Watch 1
Star 0
Fork 0
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
ab73eb2ebbaeff03d26c3ef6750e1edc71052ad7
docker-infrastructure/falco/rules
T
History
poprhythm 7c0340519c falco: tune out calibre sudoers-sed and lsyncd log-truncation false positives
Investigated recent Telegram alerts - no intrusion, both new hits trace to
benign one-offs: calibre's linuxserver.io s6-init NOPASSWD setup (same
pattern already whitelisted for obsidian) and lsyncd truncating its own
status log (not evidence-clearing).
2026-08-20 22:18:12 +00:00
..
cloud-metadata-probe.yaml
falco: scope cloud-metadata-probe past netdata's own auto-detection curl
2026-08-16 14:40:39 +00:00
db-spawned-process.yaml
add deploy-stack skill; falco: fix hook-tamper condition, add three more post-incident rules
2026-08-16 14:33:56 +00:00
git-hook-tamper.yaml
falco: fix git-hook-tamper false-positiving on every gitea push
2026-08-16 15:41:05 +00:00
miner-detect.yaml
falco: add cryptominer/runtime-security scanner wired into netdata
2026-08-08 17:41:20 +00:00
miner-pool-ports.yaml
falco: add cryptominer/runtime-security scanner wired into netdata
2026-08-08 17:41:20 +00:00
ssh-persistence.yaml
add deploy-stack skill; falco: fix hook-tamper condition, add three more post-incident rules
2026-08-16 14:33:56 +00:00
tune-noise.yaml
falco: tune out calibre sudoers-sed and lsyncd log-truncation false positives
2026-08-20 22:18:12 +00:00
unexpected-child-of-git.yaml
falco: add rules for git hook tampering and unexpected pack-service children
2026-08-16 14:24:29 +00:00
Powered by Gitea Version: 1.28.0+dev-115-gb06002f449 Page: 66ms Template: 3ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API