mirror of
https://github.com/evilsocket/opensnitch.git
synced 2026-06-08 20:27:34 +00:00
Now you can create rules to filter processes by checksum. Only md5 is
available at the moment.
There's a global configuration option that you can use to enable or
disable this feature, from the config file or from the Preferences
dialog.
As part of this feature there have been more changes:
- New proc monitor method (PROCESS CONNECTOR) that listens for
exec/exit events from the kernel.
This feature depends on CONFIG_PROC_EVENTS kernel option.
- Only one cache of active processes for ebpf and proc monitor
methods.
More info and details: #413.
24 lines
481 B
JSON
24 lines
481 B
JSON
{
|
|
"Server":
|
|
{
|
|
"Address":"unix:///tmp/osui.sock",
|
|
"LogFile":"/var/log/opensnitchd.log"
|
|
},
|
|
"DefaultAction": "allow",
|
|
"DefaultDuration": "once",
|
|
"InterceptUnknown": false,
|
|
"ProcMonitorMethod": "ebpf",
|
|
"LogLevel": 2,
|
|
"LogUTC": true,
|
|
"LogMicro": false,
|
|
"Firewall": "nftables",
|
|
"Rules": {
|
|
"EnableChecksums": false
|
|
},
|
|
"Stats": {
|
|
"MaxEvents": 150,
|
|
"MaxStats": 25,
|
|
"Workers": 6
|
|
}
|
|
}
|