Skip to content

T1166_Seuid_and_Setgid rules triggered by Zabbix agent #3

@j91321

Description

@j91321

Zabbix agents when executing custom scripts as extensions will trigger a lot of T1166_Seuid_and_Setgid rules. Since Zabbix agent usually has a lot of various checks done by custom scripts this should be excluded.

Adding

-F uid!=zabbix

to these rules should be enough (correctly installed agent should have zabbix user) to stop the rules from spamming.

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions