-
Notifications
You must be signed in to change notification settings - Fork 28
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
false positive: teleport marked CRITICAL due to multiple high risk behaviors #320
Comments
combo/stealer/credsMost of the browser mentions come from this text:
The mention of The mention of ref/words/backdoorWe're going to have to look at the source code for this one - it's referencing a backdoor behavior which seems sketch. ref/words/trojanSame /dev/tcpYeah, it uses it:
|
Looks like the
|
seen with teleport 16.0.3 - wolfi-dev/os#22915
Many of these are legitimately bizarre high-risk behaviors, I do think the rules could be fine-tuned, particularly combo/stealer/creds and net/fetch/suspicious
I'm really curious about what some of these mentions are though!
The text was updated successfully, but these errors were encountered: