diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index 6ebcc51de..5a436b33a 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -76,8 +76,8 @@ # %evt.arg.flags available for evt.dir=>, but only for umount2 # %evt.arg.name is path and available for evt.dir=< -- macro: umount - condition: (evt.type in (umount, umount2)) +# - macro: umount +# condition: (evt.type in (umount, umount2)) - macro: spawned_process condition: (evt.type in (execve, execveat) and evt.dir=<)