-
Bug
-
Resolution: Done
-
Undefined
-
None
-
None
-
False
-
False
-
** Note that this is a public ticket, please refrain from adding any sensitive data. **
Followed the instructions outlined in https://access.redhat.com/documentation/en-us/red_hat_insights/2023/html/assessing_and_reporting_malware_signatures_on_rhel_systems/malware-svc-getting-started
The test worked as expected. However, when configured for the scan, noticed that Insights Malware detection flagged files installed via HREL rpm kernel-debuginfo-4.18.0-372.32.1.el8_6.x86_64
We see the hits on files like this /usr/lib/debug/usr/lib/modules/4.18.0-372.32.1.el8_6.x86_64/kernel/net/ipv4/ipcomp.ko.debug
On the rule "XFTI_Generic_Linux_Kernel_Rootkit."