feat(go): advance validation sidecar toward production
This commit is contained in:
parent
6a06eba255
commit
f85c2e831a
92 changed files with 8881 additions and 91 deletions
49
go-agent/internal/detectors/new_suid.go
Normal file
49
go-agent/internal/detectors/new_suid.go
Normal file
|
|
@ -0,0 +1,49 @@
|
|||
// SPDX-License-Identifier: GPL-3.0-or-later
|
||||
|
||||
package detectors
|
||||
|
||||
import (
|
||||
"strings"
|
||||
|
||||
"codeberg.org/anassaeneroi/enodia-sentinal/go-agent/internal/config"
|
||||
"codeberg.org/anassaeneroi/enodia-sentinal/go-agent/internal/model"
|
||||
)
|
||||
|
||||
// NewSUID ports the Python new_suid detector (SID 100014).
|
||||
// The filesystem scan and baseline are supplied by the caller; absent values
|
||||
// remain fail-open until the sidecar gains its own slow-scan persistence.
|
||||
func NewSUID(state model.State, cfg config.Config) []model.Alert {
|
||||
if state.SUIDBinaries == nil || state.SUIDBaseline == nil {
|
||||
return []model.Alert{}
|
||||
}
|
||||
baseline := make(map[string]bool, len(state.SUIDBaseline))
|
||||
for _, path := range state.SUIDBaseline {
|
||||
baseline[path] = true
|
||||
}
|
||||
alerts := make([]model.Alert, 0)
|
||||
for _, path := range state.SUIDBinaries {
|
||||
if baseline[path] {
|
||||
continue
|
||||
}
|
||||
hot := false
|
||||
for _, directory := range cfg.SUIDHotDirs {
|
||||
directory = strings.TrimRight(directory, "/")
|
||||
if directory != "" && strings.HasPrefix(path, directory+"/") {
|
||||
hot = true
|
||||
break
|
||||
}
|
||||
}
|
||||
severity := "HIGH"
|
||||
detail := "new SUID/SGID binary: " + path
|
||||
if hot {
|
||||
severity = "CRITICAL"
|
||||
detail = "SUID/SGID binary in writable dir: " + path
|
||||
}
|
||||
alerts = append(alerts, model.Alert{
|
||||
SID: 100014, Severity: severity, Signature: "new_suid",
|
||||
Classtype: "privilege-escalation", Key: "suid:" + path,
|
||||
Detail: detail, PIDs: []int{},
|
||||
})
|
||||
}
|
||||
return alerts
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue