blob: 4686a0325a7b0bf2f2ed7b8158f63d000bbf8d64 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
|
type=SYSCALL msg=audit(1721179984.136:629): arch=c000003e syscall=59 success=yes exit=0 a0=1a16830 a1=193e6e0 a2=1a02870 a3=7ffcb50a1a20 items=2 ppid=2945 pid=3339 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:container_runtime_t:s0-s0:c0.c1023 key=(null)
type=EXECVE msg=audit(1721179984.136:629): argc=3 a0="docker" a1="start" a2="ubuntu"
type=CWD msg=audit(1721179984.136:629): cwd="/home/player"
type=PATH msg=audit(1721179984.136:629): item=0 name="/bin/docker" inode=103221779 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.136:629): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.136:629): proctitle=646F636B6572007374617274007562756E7475
---
type=ANOM_PROMISCUOUS msg=audit(1721179984.167:630): dev=vethc3c7cd5 prom=256 old_prom=0 auid=4294967295 uid=0 gid=0 ses=4294967295
type=SYSCALL msg=audit(1721179984.167:630): arch=c000003e syscall=44 success=yes exit=40 a0=e a1=c001190420 a2=28 a3=0 items=0 ppid=1 pid=1315 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="dockerd" exe="/usr/bin/dockerd" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=SOCKADDR msg=audit(1721179984.167:630): saddr=100000000000000000000000
type=PROCTITLE msg=audit(1721179984.167:630): proctitle=2F7573722F62696E2F646F636B657264002D480066643A2F2F002D2D636F6E7461696E6572643D2F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B
---
type=SYSCALL msg=audit(1721179984.170:631): arch=c000003e syscall=59 success=yes exit=0 a0=7ffdf0c1eda0 a1=7ffdf0c1e9a0 a2=55cdb48fd710 a3=8 items=2 ppid=3345 pid=3347 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:udev_t:s0-s0:c0.c1023 key=(null)
type=EXECVE msg=audit(1721179984.170:631): argc=5 a0="/usr/lib/systemd/systemd-sysctl" a1="--prefix=/net/ipv4/conf/vethee301d7" a2="--prefix=/net/ipv4/neigh/vethee301d7" a3="--prefix=/net/ipv6/conf/vethee301d7" a4="--prefix=/net/ipv6/neigh/vethee301d7"
type=CWD msg=audit(1721179984.170:631): cwd="/"
type=PATH msg=audit(1721179984.170:631): item=0 name="/usr/lib/systemd/systemd-sysctl" inode=355868 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:systemd_sysctl_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.170:631): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.170:631): proctitle=2F7573722F6C69622F73797374656D642F73797374656D642D73797363746C002D2D7072656669783D2F6E65742F697076342F636F6E662F7665746865653330316437002D2D7072656669783D2F6E65742F697076342F6E656967682F7665746865653330316437002D2D7072656669783D2F6E65742F697076362F636F6E66
---
type=SYSCALL msg=audit(1721179984.172:632): arch=c000003e syscall=59 success=yes exit=0 a0=7ffdf0c1eda0 a1=7ffdf0c1e9a0 a2=55cdb4901330 a3=8 items=2 ppid=3346 pid=3348 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:udev_t:s0-s0:c0.c1023 key=(null)
type=EXECVE msg=audit(1721179984.172:632): argc=5 a0="/usr/lib/systemd/systemd-sysctl" a1="--prefix=/net/ipv4/conf/vethc3c7cd5" a2="--prefix=/net/ipv4/neigh/vethc3c7cd5" a3="--prefix=/net/ipv6/conf/vethc3c7cd5" a4="--prefix=/net/ipv6/neigh/vethc3c7cd5"
type=CWD msg=audit(1721179984.172:632): cwd="/"
type=PATH msg=audit(1721179984.172:632): item=0 name="/usr/lib/systemd/systemd-sysctl" inode=355868 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:systemd_sysctl_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.172:632): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.172:632): proctitle=2F7573722F6C69622F73797374656D642F73797374656D642D73797363746C002D2D7072656669783D2F6E65742F697076342F636F6E662F7665746863336337636435002D2D7072656669783D2F6E65742F697076342F6E656967682F7665746863336337636435002D2D7072656669783D2F6E65742F697076362F636F6E66
---
type=SYSCALL msg=audit(1721179984.177:633): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=3345 pid=3347 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:udev_t:s0-s0:c0.c1023 key=(null)
type=SYSCALL msg=audit(1721179984.177:634): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=3346 pid=3348 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:udev_t:s0-s0:c0.c1023 key=(null)
type=PROCTITLE msg=audit(1721179984.177:634): proctitle=2F7573722F6C69622F73797374656D642F73797374656D642D73797363746C002D2D7072656669783D2F6E65742F697076342F636F6E662F7665746863336337636435002D2D7072656669783D2F6E65742F697076342F6E656967682F7665746863336337636435002D2D7072656669783D2F6E65742F697076362F636F6E66
type=PROCTITLE msg=audit(1721179984.177:633): proctitle=2F7573722F6C69622F73797374656D642F73797374656D642D73797363746C002D2D7072656669783D2F6E65742F697076342F636F6E662F7665746865653330316437002D2D7072656669783D2F6E65742F697076342F6E656967682F7665746865653330316437002D2D7072656669783D2F6E65742F697076362F636F6E66
---
---
---
type=SYSCALL msg=audit(1721179984.200:635): arch=c000003e syscall=59 success=yes exit=0 a0=c00003a450 a1=c00071c840 a2=c00048fd80 a3=0 items=1 ppid=1139 pid=3350 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="containerd-shim" exe="/usr/bin/containerd-shim-runc-v2" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179984.200:635): argc=10 a0="/usr/bin/containerd-shim-runc-v2" a1="-namespace" a2="moby" a3="-address" a4="/run/containerd/containerd.sock" a5="-publish-binary" a6="/usr/bin/containerd" a7="-id" a8="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8" a9="start"
type=CWD msg=audit(1721179984.200:635): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721179984.200:635): item=0 name="/usr/bin/containerd-shim-runc-v2" inode=100665599 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.200:635): proctitle=2F7573722F62696E2F636F6E7461696E6572642D7368696D2D72756E632D7632002D6E616D657370616365006D6F6279002D61646472657373002F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B002D7075626C6973682D62696E617279002F7573722F62696E2F636F6E7461696E657264002D69
---
type=SYSCALL msg=audit(1721179984.211:636): arch=c000003e syscall=59 success=yes exit=0 a0=c0000a69f0 a1=c00009f040 a2=c00009f080 a3=0 items=1 ppid=3350 pid=3357 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="containerd-shim" exe="/usr/bin/containerd-shim-runc-v2" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179984.211:636): argc=7 a0="/usr/bin/containerd-shim-runc-v2" a1="-namespace" a2="moby" a3="-id" a4="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8" a5="-address" a6="/run/containerd/containerd.sock"
type=CWD msg=audit(1721179984.211:636): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721179984.211:636): item=0 name="/usr/bin/containerd-shim-runc-v2" inode=100665599 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.211:636): proctitle=2F7573722F62696E2F636F6E7461696E6572642D7368696D2D72756E632D7632002D6E616D657370616365006D6F6279002D69640061376332373634663566386435383464623766393033636365646632333336656666343031343531666231303936373865613336373635336662393265356238002D61646472657373002F
---
type=SYSCALL msg=audit(1721179984.213:637): arch=c000003e syscall=231 a0=0 a1=1 a2=0 a3=4ec items=0 ppid=1139 pid=3350 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="containerd-shim" exe="/usr/bin/containerd-shim-runc-v2" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.213:637): proctitle=2F7573722F62696E2F636F6E7461696E6572642D7368696D2D72756E632D7632002D6E616D657370616365006D6F6279002D61646472657373002F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B002D7075626C6973682D62696E617279002F7573722F62696E2F636F6E7461696E657264002D69
---
type=SYSCALL msg=audit(1721179984.224:638): arch=c000003e syscall=59 success=yes exit=0 a0=c000199670 a1=c000133180 a2=c0001bc2d0 a3=0 items=2 ppid=3357 pid=3368 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179984.224:638): argc=15 a0="runc" a1="--root" a2="/var/run/docker/runtime-runc/moby" a3="--log" a4="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/log.json" a5="--log-format" a6="json" a7="create" a8="--bundle" a9="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8" a10="--pid-file" a11="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/init.pid" a12="--console-socket" a13="/tmp/pty3849963645/pty.sock" a14="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=CWD msg=audit(1721179984.224:638): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721179984.224:638): item=0 name="/usr/bin/runc" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.224:638): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.224:638): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721179984.239:639): arch=c000003e syscall=59 success=yes exit=0 a0=c000180a10 a1=c00009d8a8 a2=c0000a67d0 a3=0 items=2 ppid=3368 pid=3375 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="exe" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179984.239:639): argc=2 a0="runc" a1="init"
type=CWD msg=audit(1721179984.239:639): cwd="/var/lib/docker/overlay2/2d28d3d7bbad8e0b6ceb33a57ad027faa3ea261ff2a5ada1a6d7adc886e81c0a/merged"
type=PATH msg=audit(1721179984.239:639): item=0 name="/proc/self/exe" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.239:639): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.239:639): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721179984.250:640): arch=c000003e syscall=59 success=yes exit=0 a0=7ffd5ec41570 a1=558546109030 a2=558546109050 a3=7ffd5ec410a0 items=2 ppid=3368 pid=3375 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="7" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179984.250:640): argc=2 a0="runc" a1="init"
type=CWD msg=audit(1721179984.250:640): cwd="/var/lib/docker/overlay2/2d28d3d7bbad8e0b6ceb33a57ad027faa3ea261ff2a5ada1a6d7adc886e81c0a/merged"
type=PATH msg=audit(1721179984.250:640): item=0 name="/proc/self/fd/7" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.250:640): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.250:640): proctitle=72756E6300696E6974
---
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=filter family=2 entries=0
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=filter family=10 entries=0
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=raw family=2 entries=0
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=security family=2 entries=0
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=mangle family=2 entries=0
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=nat family=2 entries=0
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=raw family=10 entries=0
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=security family=10 entries=0
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=mangle family=10 entries=0
type=NETFILTER_CFG msg=audit(1721179984.252:641): table=nat family=10 entries=0
type=SYSCALL msg=audit(1721179984.252:641): arch=c000003e syscall=272 success=yes exit=0 a0=6c020000 a1=5623ec5cf373 a2=5623ec5d1460 a3=7ffe2c25ba20 items=0 ppid=3368 pid=3377 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc:[1:CHILD]" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.252:641): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721179984.258:642): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=3368 pid=3377 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc:[1:CHILD]" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.258:642): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721179984.260:643): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=3368 pid=3375 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc:[0:PARENT]" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.260:643): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721179984.276:644): arch=c000003e syscall=59 success=yes exit=0 a0=c0001cd230 a1=c0001c1c80 a2=c0001c1cb0 a3=0 items=2 ppid=3368 pid=3383 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="exe" exe="/usr/bin/dockerd" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179984.276:644): argc=4 a0="libnetwork-setkey" a1="-exec-root=/var/run/docker" a2="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8" a3="d6ff75a08de6"
type=CWD msg=audit(1721179984.276:644): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721179984.276:644): item=0 name="/proc/1315/exe" inode=100665603 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.276:644): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.276:644): proctitle=6C69626E6574776F726B2D7365746B6579002D657865632D726F6F743D2F7661722F72756E2F646F636B6572006137633237363466356638643538346462376639303363636564663233333665666634303134353166623130393637386561333637363533666239326535623800643666663735613038646536
---
type=SYSCALL msg=audit(1721179984.384:645): arch=c000003e syscall=231 a0=0 a1=12 a2=0 a3=558c5cbdb700 items=0 ppid=3368 pid=3383 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="exe" exe="/usr/bin/dockerd" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.384:645): proctitle=6C69626E6574776F726B2D7365746B6579002D657865632D726F6F743D2F7661722F72756E2F646F636B6572006137633237363466356638643538346462376639303363636564663233333665666634303134353166623130393637386561333637363533666239326535623800643666663735613038646536
---
type=SECCOMP msg=audit(1721179984.454:646): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=system_u:system_r:container_runtime_t:s0 pid=3378 comm="runc:[2:INIT]" sig=0 arch=c000003e syscall=439 compat=0 ip=0x5623ec13e40e code=0x50000
type=SYSCALL msg=audit(1721179984.455:647): arch=c000003e syscall=231 a0=0 a1=1 a2=c00011f2e0 a3=1500 items=0 ppid=3357 pid=3368 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.455:647): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721179984.464:648): arch=c000003e syscall=59 success=yes exit=0 a0=c0002ca180 a1=c0002cc2d0 a2=c0002984b0 a3=0 items=2 ppid=3357 pid=3392 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179984.464:648): argc=9 a0="runc" a1="--root" a2="/var/run/docker/runtime-runc/moby" a3="--log" a4="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/log.json" a5="--log-format" a6="json" a7="start" a8="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=CWD msg=audit(1721179984.464:648): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721179984.464:648): item=0 name="/usr/bin/runc" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.464:648): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.464:648): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721179984.474:649): arch=c000003e syscall=231 a0=0 a1=1 a2=0 a3=563955c730e0 items=0 ppid=3357 pid=3392 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.474:649): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721179984.474:650): arch=c000003e syscall=59 success=yes exit=0 a0=c0001e1bd0 a1=c00013cb40 a2=c0001a2840 a3=0 items=2 ppid=3357 pid=3378 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="bash" exe="/bin/bash" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721179984.474:650): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721179984.474:650): argc=1 a0="/bin/bash"
type=CWD msg=audit(1721179984.474:650): cwd="/"
type=PATH msg=audit(1721179984.474:650): item=0 name="/bin/bash" inode=38622 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.474:650): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.474:650): proctitle="/bin/bash"
---
type=SYSCALL msg=audit(1721179984.481:651): arch=c000003e syscall=59 success=yes exit=0 a0=17d58e8 a1=17d5a68 a2=17d2e08 a3=598 items=2 ppid=3398 pid=3399 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="groups" exe="/usr/bin/groups" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721179984.481:651): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721179984.481:651): argc=1 a0="groups"
type=CWD msg=audit(1721179984.481:651): cwd="/"
type=PATH msg=audit(1721179984.481:651): item=0 name="/usr/bin/groups" inode=36473 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.481:651): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.481:651): proctitle="groups"
---
type=SYSCALL msg=audit(1721179984.483:652): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffd45ecd3c8 items=0 ppid=3398 pid=3399 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="groups" exe="/usr/bin/groups" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.483:652): proctitle="groups"
---
type=SYSCALL msg=audit(1721179984.484:653): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffc48ca6888 items=0 ppid=3378 pid=3398 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="bash" exe="/bin/bash" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.484:653): proctitle="/bin/bash"
---
type=SYSCALL msg=audit(1721179984.486:654): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=4 items=0 ppid=2945 pid=3339 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:container_runtime_t:s0-s0:c0.c1023 key=(null)
type=PROCTITLE msg=audit(1721179984.486:654): proctitle=646F636B6572007374617274007562756E7475
---
type=SYSCALL msg=audit(1721179984.486:655): arch=c000003e syscall=59 success=yes exit=0 a0=17d6dc8 a1=17d6988 a2=17d2e08 a3=598 items=2 ppid=3400 pid=3401 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="dircolors" exe="/usr/bin/dircolors" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721179984.486:655): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721179984.486:655): argc=2 a0="dircolors" a1="-b"
type=CWD msg=audit(1721179984.486:655): cwd="/"
type=PATH msg=audit(1721179984.486:655): item=0 name="/usr/bin/dircolors" inode=36478 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179984.486:655): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179984.486:655): proctitle=646972636F6C6F7273002D62
---
type=SYSCALL msg=audit(1721179984.488:656): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffe9820d8d8 items=0 ppid=3400 pid=3401 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="dircolors" exe="/usr/bin/dircolors" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.488:656): proctitle=646972636F6C6F7273002D62
---
type=SYSCALL msg=audit(1721179984.488:657): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffc48ca6278 items=0 ppid=3378 pid=3400 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="bash" exe="/bin/bash" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179984.488:657): proctitle="/bin/bash"
---
type=SYSCALL msg=audit(1721179987.374:658): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=fffffffffffffe50 items=0 ppid=573 pid=3349 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-udevd" exe="/usr/lib/systemd/systemd-udevd" subj=system_u:system_r:udev_t:s0-s0:c0.c1023 key=(null)
type=PROCTITLE msg=audit(1721179987.374:658): proctitle="/usr/lib/systemd/systemd-udevd"
---
type=SYSCALL msg=audit(1721179987.374:659): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=fffffffffffffe50 items=0 ppid=573 pid=3345 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-udevd" exe="/usr/lib/systemd/systemd-udevd" subj=system_u:system_r:udev_t:s0-s0:c0.c1023 key=(null)
type=PROCTITLE msg=audit(1721179987.374:659): proctitle="/usr/lib/systemd/systemd-udevd"
---
type=SYSCALL msg=audit(1721179987.375:660): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=fffffffffffffe50 items=0 ppid=573 pid=3346 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-udevd" exe="/usr/lib/systemd/systemd-udevd" subj=system_u:system_r:udev_t:s0-s0:c0.c1023 key=(null)
type=PROCTITLE msg=audit(1721179987.375:660): proctitle="/usr/lib/systemd/systemd-udevd"
---
type=SYSCALL msg=audit(1721179998.082:661): arch=c000003e syscall=59 success=yes exit=0 a0=193ea90 a1=1a14dc0 a2=1a02870 a3=7ffcb50a1a20 items=2 ppid=2945 pid=3402 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:container_runtime_t:s0-s0:c0.c1023 key=(null)
type=EXECVE msg=audit(1721179998.082:661): argc=5 a0="docker" a1="exec" a2="ubuntu" a3="echo" a4="hello"
type=CWD msg=audit(1721179998.082:661): cwd="/home/player"
type=PATH msg=audit(1721179998.082:661): item=0 name="/bin/docker" inode=103221779 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179998.082:661): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179998.082:661): proctitle=646F636B65720065786563007562756E7475006563686F0068656C6C6F
---
type=SYSCALL msg=audit(1721179998.133:662): arch=c000003e syscall=59 success=yes exit=0 a0=c0002f4110 a1=c000206780 a2=c0001bd950 a3=0 items=2 ppid=3357 pid=3409 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179998.133:662): argc=14 a0="runc" a1="--root" a2="/var/run/docker/runtime-runc/moby" a3="--log" a4="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/log.json" a5="--log-format" a6="json" a7="exec" a8="--process" a9="/tmp/runc-process2506901255" a10="--detach" a11="--pid-file" a12="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/97c8f3af19ec98b9c452de78ce4da8c5dd864f6f0c4415a8b5ff3b5736044e68.pid" a13="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=CWD msg=audit(1721179998.133:662): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721179998.133:662): item=0 name="/usr/bin/runc" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179998.133:662): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179998.133:662): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721179998.161:663): arch=c000003e syscall=59 success=yes exit=0 a0=c000162a00 a1=c000155770 a2=c000157700 a3=0 items=2 ppid=3409 pid=3417 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="exe" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179998.161:663): argc=2 a0="runc" a1="init"
type=CWD msg=audit(1721179998.161:663): cwd="/var/lib/docker/overlay2/2d28d3d7bbad8e0b6ceb33a57ad027faa3ea261ff2a5ada1a6d7adc886e81c0a/merged"
type=PATH msg=audit(1721179998.161:663): item=0 name="/proc/self/exe" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179998.161:663): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179998.161:663): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721179998.186:664): arch=c000003e syscall=59 success=yes exit=0 a0=7ffc53fec590 a1=560e20a66030 a2=560e20a66050 a3=7ffc53fec0e0 items=2 ppid=3409 pid=3417 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="5" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721179998.186:664): argc=2 a0="runc" a1="init"
type=CWD msg=audit(1721179998.186:664): cwd="/var/lib/docker/overlay2/2d28d3d7bbad8e0b6ceb33a57ad027faa3ea261ff2a5ada1a6d7adc886e81c0a/merged"
type=PATH msg=audit(1721179998.186:664): item=0 name="/proc/self/fd/5" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179998.186:664): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179998.186:664): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721179998.189:665): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=3409 pid=3418 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc:[1:CHILD]" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179998.189:665): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721179998.190:666): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=3409 pid=3417 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc:[0:PARENT]" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179998.190:666): proctitle=72756E6300696E6974
---
type=SECCOMP msg=audit(1721179998.218:667): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=system_u:system_r:container_runtime_t:s0 pid=3419 comm="runc:[2:INIT]" sig=0 arch=c000003e syscall=439 compat=0 ip=0x5601dc7be40e code=0x50000
type=SYSCALL msg=audit(1721179998.218:668): arch=c000003e syscall=231 a0=0 a1=0 a2=c0000ef2e0 a3=c0002e0300 items=0 ppid=3357 pid=3409 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179998.218:668): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721179998.218:669): arch=c000003e syscall=59 success=yes exit=0 a0=c0000f86b0 a1=c0001173b0 a2=c0000243c0 a3=0 items=2 ppid=3409 pid=3419 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="echo" exe="/bin/echo" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721179998.218:669): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721179998.218:669): argc=2 a0="echo" a1="hello"
type=CWD msg=audit(1721179998.218:669): cwd="/"
type=PATH msg=audit(1721179998.218:669): item=0 name="/bin/echo" inode=36536 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721179998.218:669): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721179998.218:669): proctitle=6563686F0068656C6C6F
---
type=SYSCALL msg=audit(1721179998.220:670): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffc7b282148 items=0 ppid=3357 pid=3419 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="echo" exe="/bin/echo" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721179998.220:670): proctitle=6563686F0068656C6C6F
---
type=SYSCALL msg=audit(1721179998.223:671): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=4 items=0 ppid=2945 pid=3402 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:container_runtime_t:s0-s0:c0.c1023 key=(null)
type=PROCTITLE msg=audit(1721179998.223:671): proctitle=646F636B65720065786563007562756E7475006563686F0068656C6C6F
---
type=SYSCALL msg=audit(1721180008.674:672): arch=c000003e syscall=59 success=yes exit=0 a0=1a1ce20 a1=1a14dc0 a2=1a02870 a3=7ffcb50a1a20 items=2 ppid=2945 pid=3425 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:container_runtime_t:s0-s0:c0.c1023 key=(null)
type=EXECVE msg=audit(1721180008.674:672): argc=5 a0="docker" a1="exec" a2="-it" a3="ubuntu" a4="/bin/bash"
type=CWD msg=audit(1721180008.674:672): cwd="/home/player"
type=PATH msg=audit(1721180008.674:672): item=0 name="/bin/docker" inode=103221779 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180008.674:672): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180008.674:672): proctitle=646F636B65720065786563002D6974007562756E7475002F62696E2F62617368
---
type=SYSCALL msg=audit(1721180008.720:673): arch=c000003e syscall=59 success=yes exit=0 a0=c0002f42d0 a1=c000222240 a2=c0001bc6f0 a3=0 items=2 ppid=3357 pid=3432 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721180008.720:673): argc=16 a0="runc" a1="--root" a2="/var/run/docker/runtime-runc/moby" a3="--log" a4="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/log.json" a5="--log-format" a6="json" a7="exec" a8="--process" a9="/tmp/runc-process201052328" a10="--console-socket" a11="/tmp/pty3160677574/pty.sock" a12="--detach" a13="--pid-file" a14="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/69b39661224db9f9e941b75da99f144a31c3ffb06ec0ea57981d4fe325d499b5.pid" a15="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=CWD msg=audit(1721180008.720:673): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721180008.720:673): item=0 name="/usr/bin/runc" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180008.720:673): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180008.720:673): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721180008.736:674): arch=c000003e syscall=59 success=yes exit=0 a0=c000194a00 a1=c000185770 a2=c000187780 a3=0 items=2 ppid=3432 pid=3440 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="exe" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721180008.736:674): argc=2 a0="runc" a1="init"
type=CWD msg=audit(1721180008.736:674): cwd="/var/lib/docker/overlay2/2d28d3d7bbad8e0b6ceb33a57ad027faa3ea261ff2a5ada1a6d7adc886e81c0a/merged"
type=PATH msg=audit(1721180008.736:674): item=0 name="/proc/self/exe" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180008.736:674): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180008.736:674): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721180008.749:675): arch=c000003e syscall=59 success=yes exit=0 a0=7ffcaa036920 a1=55a755913030 a2=55a755913050 a3=7ffcaa036460 items=2 ppid=3432 pid=3440 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="6" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721180008.749:675): argc=2 a0="runc" a1="init"
type=CWD msg=audit(1721180008.749:675): cwd="/var/lib/docker/overlay2/2d28d3d7bbad8e0b6ceb33a57ad027faa3ea261ff2a5ada1a6d7adc886e81c0a/merged"
type=PATH msg=audit(1721180008.749:675): item=0 name="/proc/self/fd/6" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180008.749:675): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180008.749:675): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721180008.753:676): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=3432 pid=3441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc:[1:CHILD]" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180008.753:676): proctitle=72756E6300696E6974
---
type=SYSCALL msg=audit(1721180008.755:677): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=3432 pid=3440 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc:[0:PARENT]" exe="/" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180008.755:677): proctitle=72756E6300696E6974
---
type=SECCOMP msg=audit(1721180008.785:678): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=system_u:system_r:container_runtime_t:s0 pid=3442 comm="runc:[2:INIT]" sig=0 arch=c000003e syscall=439 compat=0 ip=0x55595d8d340e code=0x50000
type=SYSCALL msg=audit(1721180008.787:679): arch=c000003e syscall=231 a0=0 a1=1 a2=c00011f2e0 a3=14b0 items=0 ppid=3357 pid=3432 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180008.787:679): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721180008.787:680): arch=c000003e syscall=59 success=yes exit=0 a0=c000188680 a1=c000140850 a2=c0001507b0 a3=0 items=2 ppid=3357 pid=3442 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="bash" exe="/bin/bash" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721180008.787:680): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721180008.787:680): argc=1 a0="/bin/bash"
type=CWD msg=audit(1721180008.787:680): cwd="/"
type=PATH msg=audit(1721180008.787:680): item=0 name="/bin/bash" inode=38622 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180008.787:680): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180008.787:680): proctitle="/bin/bash"
---
type=SYSCALL msg=audit(1721180008.794:681): arch=c000003e syscall=59 success=yes exit=0 a0=8fe8e8 a1=8fea68 a2=8fbe08 a3=598 items=2 ppid=3447 pid=3448 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="groups" exe="/usr/bin/groups" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721180008.794:681): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721180008.794:681): argc=1 a0="groups"
type=CWD msg=audit(1721180008.794:681): cwd="/"
type=PATH msg=audit(1721180008.794:681): item=0 name="/usr/bin/groups" inode=36473 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180008.794:681): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180008.794:681): proctitle="groups"
---
type=SYSCALL msg=audit(1721180008.796:682): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffd80931ef8 items=0 ppid=3447 pid=3448 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="groups" exe="/usr/bin/groups" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180008.796:682): proctitle="groups"
---
type=SYSCALL msg=audit(1721180008.796:683): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffe2dd07ff8 items=0 ppid=3442 pid=3447 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="bash" exe="/bin/bash" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180008.796:683): proctitle="/bin/bash"
---
type=SYSCALL msg=audit(1721180008.798:684): arch=c000003e syscall=59 success=yes exit=0 a0=8ffdc8 a1=8ff988 a2=8fbe08 a3=598 items=2 ppid=3449 pid=3450 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="dircolors" exe="/usr/bin/dircolors" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721180008.798:684): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721180008.798:684): argc=2 a0="dircolors" a1="-b"
type=CWD msg=audit(1721180008.798:684): cwd="/"
type=PATH msg=audit(1721180008.798:684): item=0 name="/usr/bin/dircolors" inode=36478 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180008.798:684): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180008.798:684): proctitle=646972636F6C6F7273002D62
---
type=SYSCALL msg=audit(1721180008.799:685): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffc18145518 items=0 ppid=3449 pid=3450 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="dircolors" exe="/usr/bin/dircolors" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180008.799:685): proctitle=646972636F6C6F7273002D62
---
type=SYSCALL msg=audit(1721180008.799:686): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffe2dd079e8 items=0 ppid=3442 pid=3449 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="bash" exe="/bin/bash" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180008.799:686): proctitle="/bin/bash"
---
type=SYSCALL msg=audit(1721180010.254:687): arch=c000003e syscall=59 success=yes exit=0 a0=920488 a1=8fcb48 a2=8fbe08 a3=598 items=2 ppid=3442 pid=3451 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="ls" exe="/bin/ls" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721180010.254:687): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721180010.254:687): argc=2 a0="ls" a1="--color=auto"
type=CWD msg=audit(1721180010.254:687): cwd="/"
type=PATH msg=audit(1721180010.254:687): item=0 name="/bin/ls" inode=39943 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180010.254:687): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180010.254:687): proctitle=6C73002D2D636F6C6F723D6175746F
---
type=SYSCALL msg=audit(1721180010.260:688): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7f7cb1fcb250 items=0 ppid=3442 pid=3451 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="ls" exe="/bin/ls" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180010.260:688): proctitle=6C73002D2D636F6C6F723D6175746F
---
type=SYSCALL msg=audit(1721180016.276:689): arch=c000003e syscall=59 success=yes exit=0 a0=9205a8 a1=9206c8 a2=8fbe08 a3=598 items=2 ppid=3442 pid=3452 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="ls" exe="/bin/ls" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721180016.276:689): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721180016.276:689): argc=3 a0="ls" a1="--color=auto" a2="-alF"
type=CWD msg=audit(1721180016.276:689): cwd="/"
type=PATH msg=audit(1721180016.276:689): item=0 name="/bin/ls" inode=39943 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180016.276:689): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180016.276:689): proctitle=6C73002D2D636F6C6F723D6175746F002D616C46
---
type=SYSCALL msg=audit(1721180016.284:690): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7f80840d8140 items=0 ppid=3442 pid=3452 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="ls" exe="/bin/ls" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180016.284:690): proctitle=6C73002D2D636F6C6F723D6175746F002D616C46
---
type=SYSCALL msg=audit(1721180019.825:691): arch=c000003e syscall=59 success=yes exit=0 a0=920248 a1=920148 a2=8fbe08 a3=598 items=2 ppid=3442 pid=3453 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="vim" exe="/usr/bin/vim.basic" subj=system_u:system_r:spc_t:s0 key=(null)
type=BPRM_FCAPS msg=audit(1721180019.825:691): fver=0 fp=0000000000000000 fi=0000000000000000 fe=0 old_pp=00000000a80425fb old_pi=0000000000000000 old_pe=00000000a80425fb old_pa=0000000000000000 pp=00000000a80425fb pi=0000000000000000 pe=00000000a80425fb pa=0000000000000000
type=EXECVE msg=audit(1721180019.825:691): argc=1 a0="vim"
type=CWD msg=audit(1721180019.825:691): cwd="/"
type=PATH msg=audit(1721180019.825:691): item=0 name="/usr/bin/vim" inode=36570 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180019.825:691): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=38631 dev=00:29 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_share_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180019.825:691): proctitle="vim"
---
type=SYSCALL msg=audit(1721180023.165:692): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7f509814f140 items=0 ppid=3442 pid=3453 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="vim" exe="/usr/bin/vim.basic" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180023.165:692): proctitle="vim"
---
type=SYSCALL msg=audit(1721180025.784:693): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffe2dd08968 items=0 ppid=3357 pid=3442 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=4294967295 comm="bash" exe="/bin/bash" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180025.784:693): proctitle="/bin/bash"
---
type=SYSCALL msg=audit(1721180025.790:694): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=4 items=0 ppid=2945 pid=3425 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:container_runtime_t:s0-s0:c0.c1023 key=(null)
type=PROCTITLE msg=audit(1721180025.790:694): proctitle=646F636B65720065786563002D6974007562756E7475002F62696E2F62617368
---
type=SYSCALL msg=audit(1721180030.377:695): arch=c000003e syscall=59 success=yes exit=0 a0=1945bb0 a1=1a16800 a2=1a02870 a3=7ffcb50a1a20 items=2 ppid=2945 pid=3454 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:container_runtime_t:s0-s0:c0.c1023 key=(null)
type=EXECVE msg=audit(1721180030.377:695): argc=3 a0="docker" a1="stop" a2="ubuntu"
type=CWD msg=audit(1721180030.377:695): cwd="/home/player"
type=PATH msg=audit(1721180030.377:695): item=0 name="/bin/docker" inode=103221779 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180030.377:695): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180030.377:695): proctitle=646F636B65720073746F70007562756E7475
---
type=SYSCALL msg=audit(1721180030.417:696): arch=c000003e syscall=59 success=yes exit=0 a0=c0002f4080 a1=c000024a80 a2=c00009d890 a3=0 items=2 ppid=3357 pid=3461 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721180030.417:696): argc=10 a0="runc" a1="--root" a2="/var/run/docker/runtime-runc/moby" a3="--log" a4="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/log.json" a5="--log-format" a6="json" a7="kill" a8="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8" a9="15"
type=CWD msg=audit(1721180030.417:696): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721180030.417:696): item=0 name="/usr/bin/runc" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180030.417:696): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180030.417:696): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721180030.429:697): arch=c000003e syscall=231 a0=0 a1=1 a2=0 a3=0 items=0 ppid=3357 pid=3461 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180030.429:697): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721180030.429:698): arch=c000003e syscall=231 a0=0 a1=3c a2=0 a3=7ffc48ca71f8 items=0 ppid=3357 pid=3378 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="bash" exe="/bin/bash" subj=system_u:system_r:spc_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180030.429:698): proctitle="/bin/bash"
---
type=SYSCALL msg=audit(1721180030.451:699): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=57 pid=3467 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-cgroups" exe="/usr/lib/systemd/systemd-cgroups-agent" subj=system_u:system_r:init_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180030.451:699): proctitle=2F7573722F6C69622F73797374656D642F73797374656D642D6367726F7570732D6167656E74002F646F636B65722F61376332373634663566386435383464623766393033636365646632333336656666343031343531666231303936373865613336373635336662393265356238
---
type=SYSCALL msg=audit(1721180030.453:700): arch=c000003e syscall=59 success=yes exit=0 a0=c000012400 a1=c0001c2140 a2=c00007e9f0 a3=0 items=2 ppid=3357 pid=3468 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721180030.453:700): argc=9 a0="runc" a1="--root" a2="/var/run/docker/runtime-runc/moby" a3="--log" a4="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/log.json" a5="--log-format" a6="json" a7="delete" a8="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=CWD msg=audit(1721180030.453:700): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721180030.453:700): item=0 name="/usr/bin/runc" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180030.453:700): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180030.453:700): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721180030.485:701): arch=c000003e syscall=231 a0=0 a1=56455e45cce0 a2=0 a3=c000048890 items=0 ppid=3357 pid=3468 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180030.485:701): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721180030.488:702): arch=c000003e syscall=231 a0=0 a1=c0001d0300 a2=0 a3=10 items=0 ppid=1 pid=3357 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="containerd-shim" exe="/usr/bin/containerd-shim-runc-v2" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180030.488:702): proctitle=2F7573722F62696E2F636F6E7461696E6572642D7368696D2D72756E632D7632002D6E616D657370616365006D6F6279002D69640061376332373634663566386435383464623766393033636365646632333336656666343031343531666231303936373865613336373635336662393265356238002D61646472657373002F
---
type=SYSCALL msg=audit(1721180030.488:703): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=57 pid=3473 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-cgroups" exe="/usr/lib/systemd/systemd-cgroups-agent" subj=system_u:system_r:init_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180030.488:703): proctitle=2F7573722F6C69622F73797374656D642F73797374656D642D6367726F7570732D6167656E74002F646F636B6572
---
type=SYSCALL msg=audit(1721180030.490:704): arch=c000003e syscall=59 success=yes exit=0 a0=c00054a300 a1=c00030b260 a2=c000514400 a3=0 items=1 ppid=1139 pid=3474 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="containerd-shim" exe="/usr/bin/containerd-shim-runc-v2" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721180030.490:704): argc=12 a0="/usr/bin/containerd-shim-runc-v2" a1="-namespace" a2="moby" a3="-address" a4="/run/containerd/containerd.sock" a5="-publish-binary" a6="/usr/bin/containerd" a7="-id" a8="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8" a9="-bundle" a10="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8" a11="delete"
type=CWD msg=audit(1721180030.490:704): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721180030.490:704): item=0 name="/usr/bin/containerd-shim-runc-v2" inode=100665599 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180030.490:704): proctitle=2F7573722F62696E2F636F6E7461696E6572642D7368696D2D72756E632D7632002D6E616D657370616365006D6F6279002D61646472657373002F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B002D7075626C6973682D62696E617279002F7573722F62696E2F636F6E7461696E657264002D69
---
type=SYSCALL msg=audit(1721180030.497:705): arch=c000003e syscall=59 success=yes exit=0 a0=c0001ac3e0 a1=c000180480 a2=c00019c4b0 a3=0 items=2 ppid=3474 pid=3480 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=EXECVE msg=audit(1721180030.497:705): argc=10 a0="runc" a1="--root" a2="/var/run/docker/runtime-runc/moby" a3="--log" a4="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8/log.json" a5="--log-format" a6="json" a7="delete" a8="--force" a9="a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=CWD msg=audit(1721180030.497:705): cwd="/run/containerd/io.containerd.runtime.v2.task/moby/a7c2764f5f8d584db7f903ccedf2336eff401451fb109678ea367653fb92e5b8"
type=PATH msg=audit(1721180030.497:705): item=0 name="/usr/bin/runc" inode=100665601 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_runtime_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180030.497:705): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180030.497:705): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721180030.504:706): arch=c000003e syscall=231 a0=0 a1=36 a2=0 a3=8c3 items=0 ppid=3474 pid=3480 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180030.504:706): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F61376332373634663566386435383464623766393033636365
---
type=SYSCALL msg=audit(1721180030.505:707): arch=c000003e syscall=231 a0=0 a1=1 a2=0 a3=0 items=0 ppid=1139 pid=3474 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="containerd-shim" exe="/usr/bin/containerd-shim-runc-v2" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=PROCTITLE msg=audit(1721180030.505:707): proctitle=2F7573722F62696E2F636F6E7461696E6572642D7368696D2D72756E632D7632002D6E616D657370616365006D6F6279002D61646472657373002F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B002D7075626C6973682D62696E617279002F7573722F62696E2F636F6E7461696E657264002D69
---
type=SYSCALL msg=audit(1721180030.539:708): arch=c000003e syscall=59 success=yes exit=0 a0=7ffdf0c1eda0 a1=7ffdf0c1e9a0 a2=55cdb4902ea0 a3=8 items=2 ppid=3486 pid=3487 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:udev_t:s0-s0:c0.c1023 key=(null)
type=EXECVE msg=audit(1721180030.539:708): argc=5 a0="/usr/lib/systemd/systemd-sysctl" a1="--prefix=/net/ipv4/conf/vethee301d7" a2="--prefix=/net/ipv4/neigh/vethee301d7" a3="--prefix=/net/ipv6/conf/vethee301d7" a4="--prefix=/net/ipv6/neigh/vethee301d7"
type=CWD msg=audit(1721180030.539:708): cwd="/"
type=PATH msg=audit(1721180030.539:708): item=0 name="/usr/lib/systemd/systemd-sysctl" inode=355868 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:systemd_sysctl_exec_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PATH msg=audit(1721180030.539:708): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=65140 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0
type=PROCTITLE msg=audit(1721180030.539:708): proctitle=2F7573722F6C69622F73797374656D642F73797374656D642D73797363746C002D2D7072656669783D2F6E65742F697076342F636F6E662F7665746865653330316437002D2D7072656669783D2F6E65742F697076342F6E656967682F7665746865653330316437002D2D7072656669783D2F6E65742F697076362F636F6E66
---
type=SYSCALL msg=audit(1721180030.542:709): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=ffffffffffffff60 items=0 ppid=3486 pid=3487 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:udev_t:s0-s0:c0.c1023 key=(null)
type=PROCTITLE msg=audit(1721180030.542:709): proctitle=2F7573722F6C69622F73797374656D642F73797374656D642D73797363746C002D2D7072656669783D2F6E65742F697076342F636F6E662F7665746865653330316437002D2D7072656669783D2F6E65742F697076342F6E656967682F7665746865653330316437002D2D7072656669783D2F6E65742F697076362F636F6E66
---
type=ANOM_PROMISCUOUS msg=audit(1721180030.543:710): dev=vethc3c7cd5 prom=0 old_prom=256 auid=4294967295 uid=0 gid=0 ses=4294967295
type=SYSCALL msg=audit(1721180030.543:710): arch=c000003e syscall=44 success=yes exit=32 a0=e a1=c0012182a0 a2=20 a3=0 items=0 ppid=1 pid=1315 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="dockerd" exe="/usr/bin/dockerd" subj=system_u:system_r:container_runtime_t:s0 key=(null)
type=SOCKADDR msg=audit(1721180030.543:710): saddr=100000000000000000000000
type=PROCTITLE msg=audit(1721180030.543:710): proctitle=2F7573722F62696E2F646F636B657264002D480066643A2F2F002D2D636F6E7461696E6572643D2F72756E2F636F6E7461696E6572642F636F6E7461696E6572642E736F636B
---
type=SYSCALL msg=audit(1721180030.598:711): arch=c000003e syscall=231 a0=0 a1=0 a2=0 a3=4 items=0 ppid=2945 pid=3454 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="docker" exe="/usr/bin/docker" subj=unconfined_u:system_r:container_runtime_t:s0-s0:c0.c1023 key=(null)
type=PROCTITLE msg=audit(1721180030.598:711): proctitle=646F636B65720073746F70007562756E7475
---
|