make falco custom rules self contained
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s

This commit is contained in:
2026-08-10 21:54:56 -04:00
parent 797e9efc15
commit 51dff6d515
+6 -3
View File
@@ -5,9 +5,12 @@
- list: sensitive_container_paths - list: sensitive_container_paths
items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config] items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config]
- macro: container_activity
condition: container.id != host
- rule: Shell spawned in container - rule: Shell spawned in container
desc: A shell process was started inside a running container. desc: A shell process was started inside a running container.
condition: spawned_process and container and proc.name in (bash, sh, ash, zsh, ksh, fish) condition: evt.type in (execve, execveat) and container_activity and proc.name in (bash, sh, ash, zsh, ksh, fish)
output: >- output: >-
Shell spawned in container Shell spawned in container
(user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline (user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline
@@ -18,7 +21,7 @@
- rule: Sensitive file modified in container - rule: Sensitive file modified in container
desc: A process attempted to write a sensitive host-like file from a container. desc: A process attempted to write a sensitive host-like file from a container.
condition: open_write and container and fd.name in (sensitive_container_paths) condition: evt.type in (open, openat, openat2) and evt.is_open_write=true and container_activity and fd.name in (sensitive_container_paths)
output: >- output: >-
Sensitive file modified in container Sensitive file modified in container
(user=%user.name command=%proc.cmdline file=%fd.name (user=%user.name command=%proc.cmdline file=%fd.name
@@ -29,7 +32,7 @@
- rule: Unexpected outbound connection from container - rule: Unexpected outbound connection from container
desc: A container opened a connection to a non-loopback address. desc: A container opened a connection to a non-loopback address.
condition: evt.type=connect and container and not fd.sip in (127.0.0.1, 0.0.0.0) condition: evt.type=connect and container_activity and not fd.sip in (127.0.0.1, 0.0.0.0)
output: >- output: >-
Outbound connection from container Outbound connection from container
(user=%user.name command=%proc.cmdline connection=%fd.name (user=%user.name command=%proc.cmdline connection=%fd.name