make falco custom rules self contained
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s
This commit is contained in:
@@ -5,9 +5,12 @@
|
||||
- list: sensitive_container_paths
|
||||
items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config]
|
||||
|
||||
- macro: container_activity
|
||||
condition: container.id != host
|
||||
|
||||
- rule: Shell spawned in container
|
||||
desc: A shell process was started inside a running container.
|
||||
condition: spawned_process and container and proc.name in (bash, sh, ash, zsh, ksh, fish)
|
||||
condition: evt.type in (execve, execveat) and container_activity and proc.name in (bash, sh, ash, zsh, ksh, fish)
|
||||
output: >-
|
||||
Shell spawned in container
|
||||
(user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline
|
||||
@@ -18,7 +21,7 @@
|
||||
|
||||
- rule: Sensitive file modified in container
|
||||
desc: A process attempted to write a sensitive host-like file from a container.
|
||||
condition: open_write and container and fd.name in (sensitive_container_paths)
|
||||
condition: evt.type in (open, openat, openat2) and evt.is_open_write=true and container_activity and fd.name in (sensitive_container_paths)
|
||||
output: >-
|
||||
Sensitive file modified in container
|
||||
(user=%user.name command=%proc.cmdline file=%fd.name
|
||||
@@ -29,7 +32,7 @@
|
||||
|
||||
- rule: Unexpected outbound connection from container
|
||||
desc: A container opened a connection to a non-loopback address.
|
||||
condition: evt.type=connect and container and not fd.sip in (127.0.0.1, 0.0.0.0)
|
||||
condition: evt.type=connect and container_activity and not fd.sip in (127.0.0.1, 0.0.0.0)
|
||||
output: >-
|
||||
Outbound connection from container
|
||||
(user=%user.name command=%proc.cmdline connection=%fd.name
|
||||
|
||||
Reference in New Issue
Block a user