eBPF文件安全数据
Last updated
Last updated
sudo bash -c 'echo >> /etc/pam.conf; echo >> /etc/pam.d/su'enable: true
inputs:
- Type: input_file_security
ProbeConfig:
FilePathFilter:
- "/etc/pam.conf"
- "/etc/pam.d"
flushers:
- Type: flusher_stdout
OnlyStdout: true
Tags: true{
"exec_id": "djQzYzExMjA0LnNxYS5uYTEzMTozNDYzNzY3NjYzNjg4MDYwMzo1OTgxMg==",
"pid": "59812",
"uid": "0",
"user": "root",
"binary": "/usr/bin/bash",
"arguments": "-c \"echo >> /etc/pam.conf; echo >> /etc/pam.d/su\"",
"cwd": "/workspace/loongcollector_community_test",
"cap.permitted": "CAP_CHOWN DAC_OVERRIDE CAP_DAC_READ_SEARCH CAP_FOWNER CAP_FSETID CAP_KILL CAP_SETGID CAP_SETUID CAP_SETPCAP CAP_LINUX_IMMUTABLE CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_ADMIN CAP_NET_RAW CAP_IPC_LOCK CAP_IPC_OWNER CAP_SYS_MODULE CAP_SYS_RAWIO CAP_SYS_CHROOT CAP_SYS_PTRACE CAP_SYS_PACCT CAP_SYS_ADMIN CAP_SYS_BOOT CAP_SYS_NICE CAP_SYS_RESOURCE CAP_SYS_TIME CAP_SYS_TTY_CONFIG CAP_MKNOD CAP_LEASE CAP_AUDIT_WRITE CAP_AUDIT_CONTROL CAP_SETFCAP CAP_MAC_OVERRIDE CAP_MAC_ADMIN CAP_SYSLOG CAP_WAKE_ALARM CAP_BLOCK_SUSPEND CAP_AUDIT_READ CAP_PERFMON CAP_BPF CAP_CHECKPOINT_RESTORE",
"cap.effective": "CAP_CHOWN DAC_OVERRIDE CAP_DAC_READ_SEARCH CAP_FOWNER CAP_FSETID CAP_KILL CAP_SETGID CAP_SETUID CAP_SETPCAP CAP_LINUX_IMMUTABLE CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_ADMIN CAP_NET_RAW CAP_IPC_LOCK CAP_IPC_OWNER CAP_SYS_MODULE CAP_SYS_RAWIO CAP_SYS_CHROOT CAP_SYS_PTRACE CAP_SYS_PACCT CAP_SYS_ADMIN CAP_SYS_BOOT CAP_SYS_NICE CAP_SYS_RESOURCE CAP_SYS_TIME CAP_SYS_TTY_CONFIG CAP_MKNOD CAP_LEASE CAP_AUDIT_WRITE CAP_AUDIT_CONTROL CAP_SETFCAP CAP_MAC_OVERRIDE CAP_MAC_ADMIN CAP_SYSLOG CAP_WAKE_ALARM CAP_BLOCK_SUSPEND CAP_AUDIT_READ CAP_PERFMON CAP_BPF CAP_CHECKPOINT_RESTORE",
"cap.inheritable": "",
"parent.exec_id": "djQzYzExMjA0LnNxYS5uYTEzMTozNDYzNzY3NjYyNTczNDkyNjo1OTgxMQ==",
"parent.pid": "59811",
"parent.uid": "0",
"parent.user": "root",
"parent.binary": "/usr/bin/sudo",
"parent.arguments": "bash -c \"echo >> /etc/pam.conf; echo >> /etc/pam.d/su\"",
"parent.cwd": "/workspace/loongcollector_community_test",
"file.path": "/etc/pam.conf",
"call_name": "write",
"event_type": "kprobe",
"__time__": "1758699420"
}