From 51dff6d515d2db86743f7c557228ea9a95a5f8b3 Mon Sep 17 00:00:00 2001 From: swaphb Date: Mon, 10 Aug 2026 21:54:56 -0400 Subject: [PATCH] make falco custom rules self contained --- falco/operator-resources/custom-rules.yaml | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/falco/operator-resources/custom-rules.yaml b/falco/operator-resources/custom-rules.yaml index 4f95a4f..80710a3 100644 --- a/falco/operator-resources/custom-rules.yaml +++ b/falco/operator-resources/custom-rules.yaml @@ -5,9 +5,12 @@ - list: sensitive_container_paths items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config] +- macro: container_activity + condition: container.id != host + - rule: Shell spawned in container desc: A shell process was started inside a running container. - condition: spawned_process and container and proc.name in (bash, sh, ash, zsh, ksh, fish) + condition: evt.type in (execve, execveat) and container_activity and proc.name in (bash, sh, ash, zsh, ksh, fish) output: >- Shell spawned in container (user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline @@ -18,7 +21,7 @@ - rule: Sensitive file modified in container desc: A process attempted to write a sensitive host-like file from a container. - condition: open_write and container and fd.name in (sensitive_container_paths) + condition: evt.type in (open, openat, openat2) and evt.is_open_write=true and container_activity and fd.name in (sensitive_container_paths) output: >- Sensitive file modified in container (user=%user.name command=%proc.cmdline file=%fd.name @@ -29,7 +32,7 @@ - rule: Unexpected outbound connection from container desc: A container opened a connection to a non-loopback address. - condition: evt.type=connect and container and not fd.sip in (127.0.0.1, 0.0.0.0) + condition: evt.type=connect and container_activity and not fd.sip in (127.0.0.1, 0.0.0.0) output: >- Outbound connection from container (user=%user.name command=%proc.cmdline connection=%fd.name