diff --git a/eventhandler.go b/eventhandler.go index 85bb864..1463e22 100644 --- a/eventhandler.go +++ b/eventhandler.go @@ -40,7 +40,7 @@ func (eventHandler *EventHandler) handleFileEvent(event *Event) { if !strings.HasPrefix(event.FileName, "/") { event.FileName = path.Join(event.Path, event.FileName) } - + //WriteLog(fmt.Sprintf("[FileWrite] file: %s syscall: %s by exe: %s", event.FileName, event.Syscall, event.Exe)) if strings.Contains(event.FileName, "post_event.json") { WriteLog("\n") WriteLog("post_event called") @@ -98,7 +98,7 @@ func isSourceCodeFile(fileName string) bool { return true } - return false + return true } func (eventHandler *EventHandler) handleProcessEvent(event *Event) { diff --git a/procmon_linux.go b/procmon_linux.go index 297782b..8e1507d 100644 --- a/procmon_linux.go +++ b/procmon_linux.go @@ -56,6 +56,7 @@ func (p *ProcessMonitor) MonitorProcesses(errc chan error) { workingDirectory = "/home/runner" } r, _ := flags.Parse(fmt.Sprintf("-a exit,always -F dir=%s -F perm=wa -S open -S openat -S rename -S renameat -k %s", workingDirectory, fileMonitorTag)) + //r, _ := flags.Parse(fmt.Sprintf("-w %s -p w -k %s", workingDirectory, fileMonitorTag)) actualBytes, _ := rule.Build(r)