make falco custom rules self contained
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s
This commit is contained in:
@@ -5,9 +5,12 @@
|
|||||||
- list: sensitive_container_paths
|
- list: sensitive_container_paths
|
||||||
items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config]
|
items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config]
|
||||||
|
|
||||||
|
- macro: container_activity
|
||||||
|
condition: container.id != host
|
||||||
|
|
||||||
- rule: Shell spawned in container
|
- rule: Shell spawned in container
|
||||||
desc: A shell process was started inside a running container.
|
desc: A shell process was started inside a running container.
|
||||||
condition: spawned_process and container and proc.name in (bash, sh, ash, zsh, ksh, fish)
|
condition: evt.type in (execve, execveat) and container_activity and proc.name in (bash, sh, ash, zsh, ksh, fish)
|
||||||
output: >-
|
output: >-
|
||||||
Shell spawned in container
|
Shell spawned in container
|
||||||
(user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline
|
(user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline
|
||||||
@@ -18,7 +21,7 @@
|
|||||||
|
|
||||||
- rule: Sensitive file modified in container
|
- rule: Sensitive file modified in container
|
||||||
desc: A process attempted to write a sensitive host-like file from a container.
|
desc: A process attempted to write a sensitive host-like file from a container.
|
||||||
condition: open_write and container and fd.name in (sensitive_container_paths)
|
condition: evt.type in (open, openat, openat2) and evt.is_open_write=true and container_activity and fd.name in (sensitive_container_paths)
|
||||||
output: >-
|
output: >-
|
||||||
Sensitive file modified in container
|
Sensitive file modified in container
|
||||||
(user=%user.name command=%proc.cmdline file=%fd.name
|
(user=%user.name command=%proc.cmdline file=%fd.name
|
||||||
@@ -29,7 +32,7 @@
|
|||||||
|
|
||||||
- rule: Unexpected outbound connection from container
|
- rule: Unexpected outbound connection from container
|
||||||
desc: A container opened a connection to a non-loopback address.
|
desc: A container opened a connection to a non-loopback address.
|
||||||
condition: evt.type=connect and container and not fd.sip in (127.0.0.1, 0.0.0.0)
|
condition: evt.type=connect and container_activity and not fd.sip in (127.0.0.1, 0.0.0.0)
|
||||||
output: >-
|
output: >-
|
||||||
Outbound connection from container
|
Outbound connection from container
|
||||||
(user=%user.name command=%proc.cmdline connection=%fd.name
|
(user=%user.name command=%proc.cmdline connection=%fd.name
|
||||||
|
|||||||
Reference in New Issue
Block a user