|
| 1 | +package main |
| 2 | + |
| 3 | +import ( |
| 4 | + "testing" |
| 5 | + |
| 6 | + "github.com/aquasecurity/tracee/signatures/signaturestest" |
| 7 | + "github.com/aquasecurity/tracee/types/detect" |
| 8 | + "github.com/aquasecurity/tracee/types/trace" |
| 9 | + "github.com/stretchr/testify/assert" |
| 10 | + "github.com/stretchr/testify/require" |
| 11 | +) |
| 12 | + |
| 13 | +func TestProcKcoreRead(t *testing.T) { |
| 14 | + testCases := []struct { |
| 15 | + Name string |
| 16 | + Events []trace.Event |
| 17 | + Findings map[string]detect.Finding |
| 18 | + }{ |
| 19 | + { |
| 20 | + Name: "should trigger detection", |
| 21 | + Events: []trace.Event{ |
| 22 | + { |
| 23 | + EventName: "security_file_open", |
| 24 | + Args: []trace.Argument{ |
| 25 | + { |
| 26 | + ArgMeta: trace.ArgMeta{ |
| 27 | + Name: "flags", |
| 28 | + }, |
| 29 | + Value: interface{}("O_RDONLY"), |
| 30 | + }, |
| 31 | + { |
| 32 | + ArgMeta: trace.ArgMeta{ |
| 33 | + Name: "pathname", |
| 34 | + }, |
| 35 | + Value: interface{}("/proc/kcore"), |
| 36 | + }, |
| 37 | + }, |
| 38 | + }, |
| 39 | + }, |
| 40 | + Findings: map[string]detect.Finding{ |
| 41 | + "TRC-96": { |
| 42 | + Data: nil, |
| 43 | + Event: trace.Event{ |
| 44 | + EventName: "security_file_open", |
| 45 | + Args: []trace.Argument{ |
| 46 | + { |
| 47 | + ArgMeta: trace.ArgMeta{ |
| 48 | + Name: "flags", |
| 49 | + }, |
| 50 | + Value: interface{}("O_RDONLY"), |
| 51 | + }, |
| 52 | + { |
| 53 | + ArgMeta: trace.ArgMeta{ |
| 54 | + Name: "pathname", |
| 55 | + }, |
| 56 | + Value: interface{}("/proc/kcore"), |
| 57 | + }, |
| 58 | + }, |
| 59 | + }.ToProtocol(), |
| 60 | + SigMetadata: detect.SignatureMetadata{ |
| 61 | + ID: "TRC-96", |
| 62 | + Version: "1", |
| 63 | + Name: "Kcore memory file read", |
| 64 | + Description: "An attempt to read /proc/kcore file was detected. KCore provides a full dump of the physical memory of the system in the core file format. Adversaries may read this file to get all of the host memory and use this information for container escape.", |
| 65 | + Properties: map[string]interface{}{ |
| 66 | + "Severity": 2, |
| 67 | + "Category": "privilege-escalation", |
| 68 | + "Technique": "Escape to Host", |
| 69 | + "Kubernetes_Technique": "", |
| 70 | + "id": "attack-pattern--4a5b7ade-8bb5-4853-84ed-23f262002665", |
| 71 | + "external_id": "T1611", |
| 72 | + }, |
| 73 | + }, |
| 74 | + }, |
| 75 | + }, |
| 76 | + }, |
| 77 | + { |
| 78 | + Name: "should not trigger detection - wrong open flags", |
| 79 | + Events: []trace.Event{ |
| 80 | + { |
| 81 | + EventName: "security_file_open", |
| 82 | + Args: []trace.Argument{ |
| 83 | + { |
| 84 | + ArgMeta: trace.ArgMeta{ |
| 85 | + Name: "pathname", |
| 86 | + }, |
| 87 | + Value: interface{}("/proc/kcore"), |
| 88 | + }, |
| 89 | + { |
| 90 | + ArgMeta: trace.ArgMeta{ |
| 91 | + Name: "flags", |
| 92 | + }, |
| 93 | + Value: interface{}("O_WRONLY"), |
| 94 | + }, |
| 95 | + }, |
| 96 | + }, |
| 97 | + }, |
| 98 | + Findings: map[string]detect.Finding{}, |
| 99 | + }, |
| 100 | + { |
| 101 | + Name: "should not trigger detection - wrong path", |
| 102 | + Events: []trace.Event{ |
| 103 | + { |
| 104 | + EventName: "security_file_open", |
| 105 | + Args: []trace.Argument{ |
| 106 | + { |
| 107 | + ArgMeta: trace.ArgMeta{ |
| 108 | + Name: "pathname", |
| 109 | + }, |
| 110 | + Value: interface{}("/proc/something"), |
| 111 | + }, |
| 112 | + { |
| 113 | + ArgMeta: trace.ArgMeta{ |
| 114 | + Name: "flags", |
| 115 | + }, |
| 116 | + Value: interface{}("O_RDONLY"), |
| 117 | + }, |
| 118 | + }, |
| 119 | + }, |
| 120 | + }, |
| 121 | + Findings: map[string]detect.Finding{}, |
| 122 | + }, |
| 123 | + } |
| 124 | + |
| 125 | + for _, tc := range testCases { |
| 126 | + t.Run(tc.Name, func(t *testing.T) { |
| 127 | + holder := signaturestest.FindingsHolder{} |
| 128 | + sig := ProcKcoreRead{} |
| 129 | + sig.Init(holder.OnFinding) |
| 130 | + |
| 131 | + for _, e := range tc.Events { |
| 132 | + err := sig.OnEvent(e.ToProtocol()) |
| 133 | + require.NoError(t, err) |
| 134 | + } |
| 135 | + assert.Equal(t, tc.Findings, holder.GroupBySigID()) |
| 136 | + }) |
| 137 | + } |
| 138 | +} |
0 commit comments