diff --git a/falco/operator-resources/container-plugin.yaml b/falco/operator-resources/container-plugin.yaml new file mode 100644 index 0000000..0077e65 --- /dev/null +++ b/falco/operator-resources/container-plugin.yaml @@ -0,0 +1,14 @@ +apiVersion: artifact.falcosecurity.dev/v1alpha1 +kind: Plugin +metadata: + name: container + namespace: falco + annotations: + argocd.argoproj.io/sync-wave: "1" +spec: + ociArtifact: + image: + repository: falcosecurity/plugins/plugin/container + tag: latest + registry: + name: ghcr.io diff --git a/falco/operator-resources/custom-rules.yaml b/falco/operator-resources/custom-rules.yaml new file mode 100644 index 0000000..4f95a4f --- /dev/null +++ b/falco/operator-resources/custom-rules.yaml @@ -0,0 +1,39 @@ +# Custom runtime detections for the portfolio baseline. +# These rules supplement the default Falco rules and are intentionally scoped +# to container activity for a clear admission-to-runtime demonstration. + +- list: sensitive_container_paths + items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config] + +- rule: Shell spawned in container + desc: A shell process was started inside a running container. + condition: spawned_process and container and proc.name in (bash, sh, ash, zsh, ksh, fish) + output: >- + Shell spawned in container + (user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline + container_id=%container.id container_image=%container.image.repository + container_name=%container.name k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name) + priority: WARNING + tags: [container, process, baseline] + +- rule: Sensitive file modified in container + desc: A process attempted to write a sensitive host-like file from a container. + condition: open_write and container and fd.name in (sensitive_container_paths) + output: >- + Sensitive file modified in container + (user=%user.name command=%proc.cmdline file=%fd.name + container_id=%container.id container_image=%container.image.repository + k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name) + priority: ERROR + tags: [container, filesystem, persistence, baseline] + +- rule: Unexpected outbound connection from container + desc: A container opened a connection to a non-loopback address. + condition: evt.type=connect and container and not fd.sip in (127.0.0.1, 0.0.0.0) + output: >- + Outbound connection from container + (user=%user.name command=%proc.cmdline connection=%fd.name + container_id=%container.id container_image=%container.image.repository + k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name) + priority: NOTICE + tags: [container, network, baseline] diff --git a/falco/operator-resources/custom-rulesfile.yaml b/falco/operator-resources/custom-rulesfile.yaml new file mode 100644 index 0000000..740b22d --- /dev/null +++ b/falco/operator-resources/custom-rulesfile.yaml @@ -0,0 +1,11 @@ +apiVersion: artifact.falcosecurity.dev/v1alpha1 +kind: Rulesfile +metadata: + name: custom-rules + namespace: falco + annotations: + argocd.argoproj.io/sync-wave: "2" +spec: + priority: 60 + configMapRef: + name: falco-custom-rules diff --git a/falco/operator-resources/kustomization.yaml b/falco/operator-resources/kustomization.yaml index 3ab8a40..0094a6a 100644 --- a/falco/operator-resources/kustomization.yaml +++ b/falco/operator-resources/kustomization.yaml @@ -4,3 +4,13 @@ resources: - namespace.yaml - falco-instance.yaml - falco-config.yaml + - container-plugin.yaml + - custom-rulesfile.yaml + +configMapGenerator: + - name: falco-custom-rules + files: + - custom-rules.yaml + +generatorOptions: + disableNameSuffixHash: true