CrowdSecC
CrowdSecโ€ข7mo ago
PopeRigby

Scenarios that have hit whitelist still showing up as alerts?

I have the following whitelist enabled, as I'm on NixOS: https://github.com/crowdsecurity/hub/blob/master/postoverflows/s01-whitelist/crowdsecurity/auditd-nix-wrappers-whitelist-process.yaml

It should be whitelisting all binaries that start follow the form of
/nix/store/*/.<binary name>-wrapped
, but it still seems to be generating alerts, like in this case:

https://gist.github.com/poperigby/97fd29e297c9843ff677d98eeef90f8e

Why is this happening?
GitHub
Main repository for crowdsec scenarios/parsers. Contribute to crowdsecurity/hub development by creating an account on GitHub.
Gist
GitHub Gist: instantly share code, notes, and snippets.
Was this page helpful?