feat(go): port process access detectors
This commit is contained in:
parent
f02509aab5
commit
fc9b5f0448
22 changed files with 554 additions and 40 deletions
|
|
@ -9,7 +9,9 @@ Current scope:
|
|||
- standard-library-only flat TOML loading for the settings used so far;
|
||||
- an injectable `/proc` process snapshot boundary;
|
||||
- a cancellable sweep loop that emits JSONL `enodia.event.v1` records;
|
||||
- exact `enodia.alert.v1` parity for the `deleted_exe` detector (SID `100012`);
|
||||
- exact `enodia.alert.v1` parity for `ld_preload` (SID `100011`),
|
||||
`deleted_exe` (`100012`), `input_snooper` (`100032`), and
|
||||
`credential_access` (`100033`);
|
||||
- `enodia.status.v1` heartbeat records with no persistence or retained-alert
|
||||
claims;
|
||||
- a shared fixture checked against the Python detector by
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue