|
42712 | 42712 | "description": "SECL expression used to target the container to apply the action on",
|
42713 | 42713 | "type": "string"
|
42714 | 42714 | },
|
| 42715 | + "hash": { |
| 42716 | + "additionalProperties": {}, |
| 42717 | + "description": "An empty object indicating the hash action", |
| 42718 | + "type": "object" |
| 42719 | + }, |
42715 | 42720 | "kill": {
|
42716 | 42721 | "description": "Kill system call applied on the container matching the rule",
|
42717 | 42722 | "properties": {
|
|
42779 | 42784 | },
|
42780 | 42785 | "type": "object"
|
42781 | 42786 | },
|
| 42787 | + "CloudWorkloadSecurityAgentRuleActionHash": { |
| 42788 | + "additionalProperties": {}, |
| 42789 | + "description": "An empty object indicating the hash action", |
| 42790 | + "type": "object" |
| 42791 | + }, |
42782 | 42792 | "CloudWorkloadSecurityAgentRuleActionMetadata": {
|
42783 | 42793 | "description": "The metadata action applied on the scope matching the rule",
|
42784 | 42794 | "properties": {
|
|
42842 | 42852 | "description": "SECL expression used to target the container to apply the action on",
|
42843 | 42853 | "type": "string"
|
42844 | 42854 | },
|
| 42855 | + "hash": { |
| 42856 | + "additionalProperties": {}, |
| 42857 | + "description": "An empty object indicating the hash action", |
| 42858 | + "type": "object" |
| 42859 | + }, |
42845 | 42860 | "kill": {
|
42846 | 42861 | "description": "Kill system call applied on the container matching the rule",
|
42847 | 42862 | "properties": {
|
|
42924 | 42939 | "description": "SECL expression used to target the container to apply the action on",
|
42925 | 42940 | "type": "string"
|
42926 | 42941 | },
|
| 42942 | + "hash": { |
| 42943 | + "additionalProperties": {}, |
| 42944 | + "description": "An empty object indicating the hash action", |
| 42945 | + "type": "object" |
| 42946 | + }, |
42927 | 42947 | "kill": {
|
42928 | 42948 | "description": "Kill system call applied on the container matching the rule",
|
42929 | 42949 | "properties": {
|
|
43146 | 43166 | "description": "SECL expression used to target the container to apply the action on",
|
43147 | 43167 | "type": "string"
|
43148 | 43168 | },
|
| 43169 | + "hash": { |
| 43170 | + "additionalProperties": {}, |
| 43171 | + "description": "An empty object indicating the hash action", |
| 43172 | + "type": "object" |
| 43173 | + }, |
43149 | 43174 | "kill": {
|
43150 | 43175 | "description": "Kill system call applied on the container matching the rule",
|
43151 | 43176 | "properties": {
|
|
43298 | 43323 | "description": "SECL expression used to target the container to apply the action on",
|
43299 | 43324 | "type": "string"
|
43300 | 43325 | },
|
| 43326 | + "hash": { |
| 43327 | + "additionalProperties": {}, |
| 43328 | + "description": "An empty object indicating the hash action", |
| 43329 | + "type": "object" |
| 43330 | + }, |
43301 | 43331 | "kill": {
|
43302 | 43332 | "description": "Kill system call applied on the container matching the rule",
|
43303 | 43333 | "properties": {
|
|
43472 | 43502 | "description": "SECL expression used to target the container to apply the action on",
|
43473 | 43503 | "type": "string"
|
43474 | 43504 | },
|
| 43505 | + "hash": { |
| 43506 | + "additionalProperties": {}, |
| 43507 | + "description": "An empty object indicating the hash action", |
| 43508 | + "type": "object" |
| 43509 | + }, |
43475 | 43510 | "kill": {
|
43476 | 43511 | "description": "Kill system call applied on the container matching the rule",
|
43477 | 43512 | "properties": {
|
|
43666 | 43701 | "description": "SECL expression used to target the container to apply the action on",
|
43667 | 43702 | "type": "string"
|
43668 | 43703 | },
|
| 43704 | + "hash": { |
| 43705 | + "additionalProperties": {}, |
| 43706 | + "description": "An empty object indicating the hash action", |
| 43707 | + "type": "object" |
| 43708 | + }, |
43669 | 43709 | "kill": {
|
43670 | 43710 | "description": "Kill system call applied on the container matching the rule",
|
43671 | 43711 | "properties": {
|
|
43929 | 43969 | "description": "SECL expression used to target the container to apply the action on",
|
43930 | 43970 | "type": "string"
|
43931 | 43971 | },
|
| 43972 | + "hash": { |
| 43973 | + "additionalProperties": {}, |
| 43974 | + "description": "An empty object indicating the hash action", |
| 43975 | + "type": "object" |
| 43976 | + }, |
43932 | 43977 | "kill": {
|
43933 | 43978 | "description": "Kill system call applied on the container matching the rule",
|
43934 | 43979 | "properties": {
|
|
44186 | 44231 | "description": "SECL expression used to target the container to apply the action on",
|
44187 | 44232 | "type": "string"
|
44188 | 44233 | },
|
| 44234 | + "hash": { |
| 44235 | + "additionalProperties": {}, |
| 44236 | + "description": "An empty object indicating the hash action", |
| 44237 | + "type": "object" |
| 44238 | + }, |
44189 | 44239 | "kill": {
|
44190 | 44240 | "description": "Kill system call applied on the container matching the rule",
|
44191 | 44241 | "properties": {
|
|
44322 | 44372 | "description": "SECL expression used to target the container to apply the action on",
|
44323 | 44373 | "type": "string"
|
44324 | 44374 | },
|
| 44375 | + "hash": { |
| 44376 | + "additionalProperties": {}, |
| 44377 | + "description": "An empty object indicating the hash action", |
| 44378 | + "type": "object" |
| 44379 | + }, |
44325 | 44380 | "kill": {
|
44326 | 44381 | "description": "Kill system call applied on the container matching the rule",
|
44327 | 44382 | "properties": {
|
|
44485 | 44540 | "description": "SECL expression used to target the container to apply the action on",
|
44486 | 44541 | "type": "string"
|
44487 | 44542 | },
|
| 44543 | + "hash": { |
| 44544 | + "additionalProperties": {}, |
| 44545 | + "description": "An empty object indicating the hash action", |
| 44546 | + "type": "object" |
| 44547 | + }, |
44488 | 44548 | "kill": {
|
44489 | 44549 | "description": "Kill system call applied on the container matching the rule",
|
44490 | 44550 | "properties": {
|
|
44673 | 44733 | "description": "SECL expression used to target the container to apply the action on",
|
44674 | 44734 | "type": "string"
|
44675 | 44735 | },
|
| 44736 | + "hash": { |
| 44737 | + "additionalProperties": {}, |
| 44738 | + "description": "An empty object indicating the hash action", |
| 44739 | + "type": "object" |
| 44740 | + }, |
44676 | 44741 | "kill": {
|
44677 | 44742 | "description": "Kill system call applied on the container matching the rule",
|
44678 | 44743 | "properties": {
|
@@ -446874,6 +446939,11 @@
|
446874 | 446939 | "description": "SECL expression used to target the container to apply the action on",
|
446875 | 446940 | "type": "string"
|
446876 | 446941 | },
|
| 446942 | + "hash": { |
| 446943 | + "additionalProperties": {}, |
| 446944 | + "description": "An empty object indicating the hash action", |
| 446945 | + "type": "object" |
| 446946 | + }, |
446877 | 446947 | "kill": {
|
446878 | 446948 | "description": "Kill system call applied on the container matching the rule",
|
446879 | 446949 | "properties": {
|
@@ -447203,6 +447273,11 @@
|
447203 | 447273 | "description": "SECL expression used to target the container to apply the action on",
|
447204 | 447274 | "type": "string"
|
447205 | 447275 | },
|
| 447276 | + "hash": { |
| 447277 | + "additionalProperties": {}, |
| 447278 | + "description": "An empty object indicating the hash action", |
| 447279 | + "type": "object" |
| 447280 | + }, |
447206 | 447281 | "kill": {
|
447207 | 447282 | "description": "Kill system call applied on the container matching the rule",
|
447208 | 447283 | "properties": {
|
@@ -447392,6 +447467,11 @@
|
447392 | 447467 | "description": "SECL expression used to target the container to apply the action on",
|
447393 | 447468 | "type": "string"
|
447394 | 447469 | },
|
| 447470 | + "hash": { |
| 447471 | + "additionalProperties": {}, |
| 447472 | + "description": "An empty object indicating the hash action", |
| 447473 | + "type": "object" |
| 447474 | + }, |
447395 | 447475 | "kill": {
|
447396 | 447476 | "description": "Kill system call applied on the container matching the rule",
|
447397 | 447477 | "properties": {
|
@@ -447752,7 +447832,7 @@
|
447752 | 447832 | "parameters": [
|
447753 | 447833 | {
|
447754 | 447834 | "name": "body",
|
447755 |
| - "value": "{\n \"data\": {\n \"type\": \"agent_rule\",\n \"attributes\": {\n \"name\": \"{{ unique_lower_alnum }}\",\n \"description\": \"My Agent rule\",\n \"expression\": \"exec.file.name == \\\"sh\\\"\",\n \"enabled\": true,\n \"product_tags\": [\"security:attack\", \"technique:T1059\"],\n \"actions\": [{\"set\": {\"name\": \"test_set\", \"value\": \"test_value\", \"scope\": \"process\"}}],\n \"policy_id\": \"{{ policy.data.id }}\"\n }\n }\n}" |
| 447835 | + "value": "{\n \"data\": {\n \"type\": \"agent_rule\",\n \"attributes\": {\n \"name\": \"{{ unique_lower_alnum }}\",\n \"description\": \"My Agent rule\",\n \"expression\": \"exec.file.name == \\\"sh\\\"\",\n \"enabled\": true,\n \"product_tags\": [\"security:attack\", \"technique:T1059\"],\n \"actions\": [{\"set\": {\"name\": \"test_set\", \"value\": \"test_value\", \"scope\": \"process\"}}, {\"hash\": {}}],\n \"policy_id\": \"{{ policy.data.id }}\"\n }\n }\n}" |
447756 | 447836 | }
|
447757 | 447837 | ],
|
447758 | 447838 | "step": "there is a valid \"agent_rule_rc\" in the system"
|
@@ -447942,6 +448022,11 @@
|
447942 | 448022 | "description": "SECL expression used to target the container to apply the action on",
|
447943 | 448023 | "type": "string"
|
447944 | 448024 | },
|
| 448025 | + "hash": { |
| 448026 | + "additionalProperties": {}, |
| 448027 | + "description": "An empty object indicating the hash action", |
| 448028 | + "type": "object" |
| 448029 | + }, |
447945 | 448030 | "kill": {
|
447946 | 448031 | "description": "Kill system call applied on the container matching the rule",
|
447947 | 448032 | "properties": {
|
@@ -448319,6 +448404,11 @@
|
448319 | 448404 | "description": "SECL expression used to target the container to apply the action on",
|
448320 | 448405 | "type": "string"
|
448321 | 448406 | },
|
| 448407 | + "hash": { |
| 448408 | + "additionalProperties": {}, |
| 448409 | + "description": "An empty object indicating the hash action", |
| 448410 | + "type": "object" |
| 448411 | + }, |
448322 | 448412 | "kill": {
|
448323 | 448413 | "description": "Kill system call applied on the container matching the rule",
|
448324 | 448414 | "properties": {
|
@@ -448497,6 +448587,11 @@
|
448497 | 448587 | "description": "SECL expression used to target the container to apply the action on",
|
448498 | 448588 | "type": "string"
|
448499 | 448589 | },
|
| 448590 | + "hash": { |
| 448591 | + "additionalProperties": {}, |
| 448592 | + "description": "An empty object indicating the hash action", |
| 448593 | + "type": "object" |
| 448594 | + }, |
448500 | 448595 | "kill": {
|
448501 | 448596 | "description": "Kill system call applied on the container matching the rule",
|
448502 | 448597 | "properties": {
|
@@ -501871,6 +501966,11 @@
|
501871 | 501966 | "description": "SECL expression used to target the container to apply the action on",
|
501872 | 501967 | "type": "string"
|
501873 | 501968 | },
|
| 501969 | + "hash": { |
| 501970 | + "additionalProperties": {}, |
| 501971 | + "description": "An empty object indicating the hash action", |
| 501972 | + "type": "object" |
| 501973 | + }, |
501874 | 501974 | "kill": {
|
501875 | 501975 | "description": "Kill system call applied on the container matching the rule",
|
501876 | 501976 | "properties": {
|
@@ -502206,6 +502306,11 @@
|
502206 | 502306 | "description": "SECL expression used to target the container to apply the action on",
|
502207 | 502307 | "type": "string"
|
502208 | 502308 | },
|
| 502309 | + "hash": { |
| 502310 | + "additionalProperties": {}, |
| 502311 | + "description": "An empty object indicating the hash action", |
| 502312 | + "type": "object" |
| 502313 | + }, |
502209 | 502314 | "kill": {
|
502210 | 502315 | "description": "Kill system call applied on the container matching the rule",
|
502211 | 502316 | "properties": {
|
@@ -502395,6 +502500,11 @@
|
502395 | 502500 | "description": "SECL expression used to target the container to apply the action on",
|
502396 | 502501 | "type": "string"
|
502397 | 502502 | },
|
| 502503 | + "hash": { |
| 502504 | + "additionalProperties": {}, |
| 502505 | + "description": "An empty object indicating the hash action", |
| 502506 | + "type": "object" |
| 502507 | + }, |
502398 | 502508 | "kill": {
|
502399 | 502509 | "description": "Kill system call applied on the container matching the rule",
|
502400 | 502510 | "properties": {
|
@@ -502937,6 +503047,11 @@
|
502937 | 503047 | "description": "SECL expression used to target the container to apply the action on",
|
502938 | 503048 | "type": "string"
|
502939 | 503049 | },
|
| 503050 | + "hash": { |
| 503051 | + "additionalProperties": {}, |
| 503052 | + "description": "An empty object indicating the hash action", |
| 503053 | + "type": "object" |
| 503054 | + }, |
502940 | 503055 | "kill": {
|
502941 | 503056 | "description": "Kill system call applied on the container matching the rule",
|
502942 | 503057 | "properties": {
|
@@ -503310,6 +503425,11 @@
|
503310 | 503425 | "description": "SECL expression used to target the container to apply the action on",
|
503311 | 503426 | "type": "string"
|
503312 | 503427 | },
|
| 503428 | + "hash": { |
| 503429 | + "additionalProperties": {}, |
| 503430 | + "description": "An empty object indicating the hash action", |
| 503431 | + "type": "object" |
| 503432 | + }, |
503313 | 503433 | "kill": {
|
503314 | 503434 | "description": "Kill system call applied on the container matching the rule",
|
503315 | 503435 | "properties": {
|
@@ -503488,6 +503608,11 @@
|
503488 | 503608 | "description": "SECL expression used to target the container to apply the action on",
|
503489 | 503609 | "type": "string"
|
503490 | 503610 | },
|
| 503611 | + "hash": { |
| 503612 | + "additionalProperties": {}, |
| 503613 | + "description": "An empty object indicating the hash action", |
| 503614 | + "type": "object" |
| 503615 | + }, |
503491 | 503616 | "kill": {
|
503492 | 503617 | "description": "Kill system call applied on the container matching the rule",
|
503493 | 503618 | "properties": {
|
|
0 commit comments