Uploaded image for project: 'Red Hat Insights Engineering'
  1. Red Hat Insights Engineering
  2. RHINENG-6808

Insights malware yara reporting on RHEL installed rpms

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • Malware
    • False
    • False
    • Hide

      None

      Show
      None

      ** Note that this is a public ticket, please refrain from adding any sensitive data. **

      Followed the instructions outlined in https://access.redhat.com/documentation/en-us/red_hat_insights/2023/html/assessing_and_reporting_malware_signatures_on_rhel_systems/malware-svc-getting-started

      The test worked as expected. However, when configured for the scan, noticed that Insights Malware detection flagged files installed via HREL rpm kernel-debuginfo-4.18.0-372.32.1.el8_6.x86_64

      We see the hits on files like this /usr/lib/debug/usr/lib/modules/4.18.0-372.32.1.el8_6.x86_64/kernel/net/ipv4/ipcomp.ko.debug
      On the rule "XFTI_Generic_Linux_Kernel_Rootkit."

              rhn-support-dkuc Dan Kuc
              rhn-support-achadha Arvinder Singh Chadha
              Anurag Sinha Anurag Sinha
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: