add falco operator plugin and custom rules
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s
This commit is contained in:
@@ -0,0 +1,14 @@
|
|||||||
|
apiVersion: artifact.falcosecurity.dev/v1alpha1
|
||||||
|
kind: Plugin
|
||||||
|
metadata:
|
||||||
|
name: container
|
||||||
|
namespace: falco
|
||||||
|
annotations:
|
||||||
|
argocd.argoproj.io/sync-wave: "1"
|
||||||
|
spec:
|
||||||
|
ociArtifact:
|
||||||
|
image:
|
||||||
|
repository: falcosecurity/plugins/plugin/container
|
||||||
|
tag: latest
|
||||||
|
registry:
|
||||||
|
name: ghcr.io
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
# Custom runtime detections for the portfolio baseline.
|
||||||
|
# These rules supplement the default Falco rules and are intentionally scoped
|
||||||
|
# to container activity for a clear admission-to-runtime demonstration.
|
||||||
|
|
||||||
|
- list: sensitive_container_paths
|
||||||
|
items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config]
|
||||||
|
|
||||||
|
- rule: Shell spawned in container
|
||||||
|
desc: A shell process was started inside a running container.
|
||||||
|
condition: spawned_process and container and proc.name in (bash, sh, ash, zsh, ksh, fish)
|
||||||
|
output: >-
|
||||||
|
Shell spawned in container
|
||||||
|
(user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline
|
||||||
|
container_id=%container.id container_image=%container.image.repository
|
||||||
|
container_name=%container.name k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name)
|
||||||
|
priority: WARNING
|
||||||
|
tags: [container, process, baseline]
|
||||||
|
|
||||||
|
- rule: Sensitive file modified in container
|
||||||
|
desc: A process attempted to write a sensitive host-like file from a container.
|
||||||
|
condition: open_write and container and fd.name in (sensitive_container_paths)
|
||||||
|
output: >-
|
||||||
|
Sensitive file modified in container
|
||||||
|
(user=%user.name command=%proc.cmdline file=%fd.name
|
||||||
|
container_id=%container.id container_image=%container.image.repository
|
||||||
|
k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name)
|
||||||
|
priority: ERROR
|
||||||
|
tags: [container, filesystem, persistence, baseline]
|
||||||
|
|
||||||
|
- rule: Unexpected outbound connection from container
|
||||||
|
desc: A container opened a connection to a non-loopback address.
|
||||||
|
condition: evt.type=connect and container and not fd.sip in (127.0.0.1, 0.0.0.0)
|
||||||
|
output: >-
|
||||||
|
Outbound connection from container
|
||||||
|
(user=%user.name command=%proc.cmdline connection=%fd.name
|
||||||
|
container_id=%container.id container_image=%container.image.repository
|
||||||
|
k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name)
|
||||||
|
priority: NOTICE
|
||||||
|
tags: [container, network, baseline]
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
apiVersion: artifact.falcosecurity.dev/v1alpha1
|
||||||
|
kind: Rulesfile
|
||||||
|
metadata:
|
||||||
|
name: custom-rules
|
||||||
|
namespace: falco
|
||||||
|
annotations:
|
||||||
|
argocd.argoproj.io/sync-wave: "2"
|
||||||
|
spec:
|
||||||
|
priority: 60
|
||||||
|
configMapRef:
|
||||||
|
name: falco-custom-rules
|
||||||
@@ -4,3 +4,13 @@ resources:
|
|||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
- falco-instance.yaml
|
- falco-instance.yaml
|
||||||
- falco-config.yaml
|
- falco-config.yaml
|
||||||
|
- container-plugin.yaml
|
||||||
|
- custom-rulesfile.yaml
|
||||||
|
|
||||||
|
configMapGenerator:
|
||||||
|
- name: falco-custom-rules
|
||||||
|
files:
|
||||||
|
- custom-rules.yaml
|
||||||
|
|
||||||
|
generatorOptions:
|
||||||
|
disableNameSuffixHash: true
|
||||||
|
|||||||
Reference in New Issue
Block a user