Detecting Container Escape With Falco Rules

Writes and tunes Falco rule syntax for container escape detection - conditions, macros, lists, priorities, and output fields - covering host filesystem mounts, sensitive host path access, kernel module loading, and privileged capability abuse, including how to drive down false positives. Use when authoring or tuning a specific Falco rule for breakout behaviour, or triaging a noisy escape-related Falco alert. Keywords: Falco rule, macro, list, condition, priority, falco_rules.local.yaml, tuning, false positive. Do not use for deploying and operating Falco itself - use detecting-container-runtime-threats-with-falco; for tool-agnostic escape signals use detecting-container-escape-attempts.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/detecting-container-escape-with-falco-rules commit f3a4edded9

Frequently asked questions

npx skillmds@latest add gabrielmoreira/detecting-container-escape-with-falco-rules