diff --git a/audit.rules b/audit.rules index d973b98..e8c501e 100644 --- a/audit.rules +++ b/audit.rules @@ -609,59 +609,37 @@ -w /usr/bin/grep -p x -k string_search -w /usr/bin/egrep -p x -k string_search -w /usr/bin/ugrep -p x -k string_search -### macOS --w /usr/local/bin/grep -p x -k string_search --w /usr/local/bin/egrep -p x -k string_search --w /usr/local/bin/ugrep -p x -k string_search ### https://github.com/tmbinc/bgrep -w /usr/bin/bgrep -p x -k string_search -### macOS --w /usr/local/bin/bgrep -p x -k string_search ### https://github.com/BurntSushi/ripgrep -w /usr/bin/rg -p x -k string_search -### macOS --w /usr/local/bin/rg -p x -k string_search ### https://github.com/awgn/cgrep -w /usr/bin/cgrep -p x -k string_search -### macOS --w /usr/local/bin/cgrep -p x -k string_search ### https://github.com/jpr5/ngrep -w /usr/bin/ngrep -p x -k string_search -### macOS --w /usr/local/bin/ngrep -p x -k string_search ### https://github.com/vrothberg/vgrep -w /usr/bin/vgrep -p x -k string_search -### macOS --w /usr/local/bin/vgrep -p x -k string_search ### https://github.com/monochromegane/the_platinum_searcher -w /usr/bin/pt -p x -k string_search -### macOS --w /usr/local/bin/pt -p x -k string_search ### https://github.com/gvansickle/ucg -w /usr/bin/ucg -p x -k string_search -### macOS --w /usr/local/bin/ucg -p x -k string_search ### https://github.com/ggreer/the_silver_searcher -w /usr/bin/ag -p x -k string_search -### macOS --w /usr/local/bin/ag -p x -k string_search ### https://github.com/beyondgrep/ack3 ### https://beyondgrep.com -w /usr/bin/ack -p x -k string_search -w /usr/local/bin/ack -p x -k string_search -w /usr/bin/semgrep -p x -k string_search -### macOS --w /usr/local/bin/semgrep -p x -k string_search ## Docker -w /usr/bin/dockerd -k docker @@ -684,45 +662,6 @@ -w /usr/bin/virt-manager -p x -k virt-manager -w /usr/bin/VBoxManage -p x -k VBoxManage -#### VirtualBox on macOS - --w /usr/local/bin/VirtualBox -p x -k virt_tool --w /usr/local/bin/VirtualBoxVM -p x -k virt_tool --w /usr/local/bin/VBoxManage -p x -k virt_tool --w /usr/local/bin/VBoxVRDP -p x -k virt_tool --w /usr/local/bin/VBoxHeadless -p x -k virt_tool --w /usr/local/bin/vboxwebsrv -p x -k virt_tool --w /usr/local/bin/VBoxBugReport -p x -k virt_tool --w /usr/local/bin/VBoxBalloonCtrl -p x -k virt_tool --w /usr/local/bin/VBoxAutostart -p x -k virt_tool --w /usr/local/bin/VBoxDTrace -p x -k virt_tool --w /usr/local/bin/vbox-img -p x -k virt_tool --w /Library/LaunchDaemons/org.virtualbox.startup.plist -p x -k virt_tool --w /Library/Application Support/VirtualBox/LaunchDaemons/ -p x -k virt_tool --w /Library/Application Support/VirtualBox/VBoxDrv.kext/ -p x -k virt_tool --w /Library/Application Support/VirtualBox/VBoxUSB.kext/ -p x -k virt_tool --w /Library/Application Support/VirtualBox/VBoxNetFlt.kext/ -p x -k virt_tool --w /Library/Application Support/VirtualBox/VBoxNetAdp.kext/ -p x -k virt_tool - -### Parallels Desktop on macOS - --w /usr/local/bin/prl_convert -p x -k virt_tool --w /usr/local/bin/prl_disk_tool -p x -k virt_tool --w /usr/local/bin/prl_perf_ctl -p x -k virt_tool --w /usr/local/bin/prlcore2dmp -p x -k virt_tool --w /usr/local/bin/prlctl -p x -k virt_tool --w /usr/local/bin/prlexec -p x -k virt_tool --w /usr/local/bin/prlsrvctl -p x -k virt_tool --w /Library/Preferences/Parallels -p x -k virt_tool - -### qemu on macOS - --w /usr/local/bin/qemu-edid -p x -k virt_tool --w /usr/local/bin/qemu-img -p x -k virt_tool --w /usr/local/bin/qemu-io -p x -k virt_tool --w /usr/local/bin/qemu-nbd -p x -k virt_tool --w /usr/local/bin/qemu-system-x86_64 -p x -k virt_tool - ## Kubelet -w /usr/bin/kubelet -k kubelet