You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I’m seeing false positives for the "Sensitive file opened for reading by non-trusted program" rule after logging in via SSH. It doesn’t happen every time, but it occurs often.
The issue seems to be that proc.name is reported as 9 instead of systemd. But I'm not sure if that's an issue on my side.
Hey,
I’m seeing false positives for the "Sensitive file opened for reading by non-trusted program" rule after logging in via SSH. It doesn’t happen every time, but it occurs often.
The issue seems to be that
proc.name
is reported as9
instead ofsystemd
. But I'm not sure if that's an issue on my side.Here's an example log:
Environment
Ubuntu 24.04.1 LTS
Linux 6.8.0-52-generic
DEB
The text was updated successfully, but these errors were encountered: