Melissa Kilby

Results 64 issues of Melissa Kilby

Signed-off-by: Melissa Kilby **What type of PR is this?** /kind feature /kind rule-create **Any specific area of the project related to this PR?** /area rules **What this PR does /...

area/rules
kind/feature
kind/rule-create
release-note
dco-signoff: yes
size/S

Kicking off a discussion as result of https://github.com/falcosecurity/libs/pull/524 CI Integration / "Fun" for tool developer -> sanity for everyone :) Success Criteria: - Daily confirmation that driver state did not...

kind/feature

Signed-off-by: Melissa Kilby **What type of PR is this?** > Uncomment one (or more) `/kind ` lines: > /kind bug > /kind cleanup > /kind design /kind documentation > /kind...

kind/documentation
dco-signoff: yes
size/XXL
do-not-merge/work-in-progress
release-note-none
area/tests

**Describe the bug** It seems like when the `socket` system call is enabled in the eBPF kernel driver, sometimes during an unlucky Falco run sockets are not closing in the...

kind/bug
area/driver-bpf

Co-authored-by: Leonardo Grasso Signed-off-by: Melissa Kilby **What type of PR is this?** > Uncomment one (or more) `/kind ` lines: > /kind bug > /kind cleanup > /kind design /kind...

kind/documentation
dco-signoff: yes
release-note-none
do-not-merge/work-in-progress
size/L

Signed-off-by: Melissa Kilby **What type of PR is this?** > Uncomment one (or more) `/kind ` lines: > /kind bug /kind cleanup > /kind design /kind documentation > /kind failing-test...

kind/documentation
area/rules
kind/feature
kind/cleanup
kind/rule-update
release-note
dco-signoff: yes
size/S
do-not-merge/work-in-progress

Based on the discussion in https://github.com/falcosecurity/libs/pull/580 additional documentation in this repo (falco) can help increase technical clarity around versioning. - https://github.com/falcosecurity/libs/pull/580#discussion_r964497282 - https://github.com/falcosecurity/libs/pull/580#discussion_r964522134 CC @leogr

kind/documentation

**What type of PR is this?** > Uncomment one (or more) `/kind ` lines: > /kind bug /kind cleanup > /kind design > /kind documentation > /kind failing-test /kind feature...

kind/feature
release-note
dco-signoff: yes
size/XXL
kind/cleanup
area/driver-kmod
area/driver-bpf
area/libscap
area/libsinsp
area/driver-modern-bpf

**Motivation** Quote from https://github.com/falcosecurity/libs/pull/595 > Another kernel side signal that would like to look into and possibly add to this PR would be: > > `"Interpreter scripts"` aka text files...

kind/feature

This issue is for tracking the development of a more generic and robust solution to detect the classic drop an implant and execute it TTP called "drop+exec". In addition, perform...

kind/documentation