feat(go): advance validation sidecar toward production
This commit is contained in:
parent
6a06eba255
commit
f85c2e831a
92 changed files with 8881 additions and 91 deletions
64
go-agent/internal/events/syscall_rules_test.go
Normal file
64
go-agent/internal/events/syscall_rules_test.go
Normal file
|
|
@ -0,0 +1,64 @@
|
|||
// SPDX-License-Identifier: GPL-3.0-or-later
|
||||
|
||||
package events
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func syscallEvent(name string, arg0, arg2 uint64) SyscallEvent {
|
||||
return SyscallEvent{
|
||||
PID: 10, PPID: 1, UID: 1000, Comm: "hoxha", Syscall: name,
|
||||
Args: [6]uint64{arg0, 0, arg2},
|
||||
}
|
||||
}
|
||||
|
||||
func TestDefaultSyscallRulesMatchPython(t *testing.T) {
|
||||
engine := DefaultSyscallRuleEngine()
|
||||
tests := []struct {
|
||||
event SyscallEvent
|
||||
sid int
|
||||
}{
|
||||
{syscallEvent("mprotect", 0, 0x6), 100060},
|
||||
{syscallEvent("mmap", 0, 0x7), 100061},
|
||||
{syscallEvent("memfd_create", 0, 0), 100062},
|
||||
{syscallEvent("ptrace", 16, 0), 100063},
|
||||
{syscallEvent("ptrace", 0x4206, 0), 100063},
|
||||
{syscallEvent("prctl", 22, 0), 100064},
|
||||
{syscallEvent("seccomp", 0, 0), 100064},
|
||||
{syscallEvent("process_vm_readv", 4242, 0), 100065},
|
||||
{syscallEvent("process_vm_writev", 4242, 0), 100065},
|
||||
{syscallEvent("mlock", 0, 0), 100066},
|
||||
{syscallEvent("mlockall", 0, 0), 100066},
|
||||
}
|
||||
for _, test := range tests {
|
||||
found := false
|
||||
for _, alert := range engine.Match(test.event) {
|
||||
if alert.SID == test.sid {
|
||||
found = true
|
||||
}
|
||||
}
|
||||
if !found {
|
||||
t.Fatalf("sid %d did not match %#v", test.sid, test.event)
|
||||
}
|
||||
}
|
||||
if alerts := engine.Match(syscallEvent("mprotect", 0, 0x5)); len(alerts) != 0 {
|
||||
t.Fatalf("read+exec mprotect matched: %#v", alerts)
|
||||
}
|
||||
if alerts := engine.Match(syscallEvent("ptrace", 3, 0)); len(alerts) != 0 {
|
||||
t.Fatalf("non-sensitive ptrace matched: %#v", alerts)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSyscallAlertContract(t *testing.T) {
|
||||
event := syscallEvent("memfd_create", 1, 0)
|
||||
event.Text = "payload"
|
||||
alert := DefaultSyscallRuleEngine().Match(event)[0]
|
||||
if alert.SID != 100062 || alert.Severity != "MEDIUM" ||
|
||||
alert.Signature != "syscall_rule.fileless-execution" ||
|
||||
alert.Key != "syscall:100062:10:memfd_create:1:0" ||
|
||||
!strings.Contains(alert.Detail, "args=[0x1, 0x0, 0x0, 0x0] text=[payload]") {
|
||||
t.Fatalf("unexpected alert: %#v", alert)
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue