← All cheat sheets

FALCO

Plain-text reference · 3 KB. Read it, search it (Ctrl-F) or print it.

Runtime security tool for containers and Kubernetes. Detects
anomalous behavior using system call monitoring and custom rules.

INSTALLATION#

# Helm (Kubernetes)
helm repo add falcosecurity https://falcosecurity.github.io/charts
helm install falco falcosecurity/falco --namespace falco --create-namespace

# Debian/Ubuntu
curl -fsSL https://falco.org/repo/falcosecurity-packages.asc | sudo gpg --dearmor -o /usr/share/keyrings/falco-archive-keyring.gpg
sudo apt update && sudo apt install falco

# Docker
docker run --rm -i -t --privileged \
  -v /var/run/docker.sock:/host/var/run/docker.sock \
  -v /proc:/host/proc:ro \
  falcosecurity/falco

KEY DETECTIONS (DEFAULT RULES)#

  - Shell spawned in container
  - Container running as root
  - Sensitive file read (/etc/shadow, /etc/passwd)
  - Network tool launched in container (nmap, curl, wget)
  - Privilege escalation attempts
  - Unauthorized process in container
  - Crypto mining activity
  - Reverse shell connections
  - Namespace changes
  - Kubernetes API access anomalies
  - Binary written to /tmp or /dev/shm

CUSTOM RULES#

# /etc/falco/falco_rules.local.yaml

- rule: Detect Reverse Shell
  desc: Detect reverse shell connections
  condition: >
    spawned_process and
    proc.name in (bash, sh, zsh) and
    fd.type = ipv4 and
    fd.direction = out
  output: >
    Reverse shell detected (user=%user.name command=%proc.cmdline
    connection=%fd.name container=%container.name)
  priority: CRITICAL
  tags: [network, shell]

- rule: Detect Kubectl Exec
  desc: Detect kubectl exec into pod
  condition: >
    spawned_process and
    container and
    proc.pname = runc
  output: >
    Exec into container (user=%user.name command=%proc.cmdline
    container=%container.name pod=%k8s.pod.name)
  priority: WARNING

FALCO CONFIGURATION#

# /etc/falco/falco.yaml
json_output: true                           # JSON logs
log_level: info
stdout_output:
  enabled: true
file_output:
  enabled: true
  filename: /var/log/falco/events.log
http_output:
  enabled: true
  url: http://siem:8080/falco
grpc_output:
  enabled: true

FALCOCTL#

falcoctl driver install                     # Install kernel driver
falcoctl artifact install falco-rules       # Update rules
falcoctl artifact list                      # List available artifacts

FALCOSIDEKICK (ALERT ROUTING)#

# Route Falco alerts to:
  Slack, Teams, Discord, PagerDuty,
  Elasticsearch, Splunk, Datadog,
  AWS SNS/SQS/Lambda, GCP Pub/Sub,
  Kafka, NATS, Webhook

# Install with Helm
helm install falco falcosecurity/falco \
  --set falcosidekick.enabled=true \
  --set falcosidekick.config.slack.webhookurl=SLACK_URL

TIPS#

  - Default rules cover most container attack patterns
  - Custom rules use condition/output/priority format
  - JSON output integrates with SIEM platforms
  - Falcosidekick routes alerts to 60+ destinations
  - eBPF driver is preferred over kernel module
  - Combine with Trivy (build-time) + Falco (runtime)
  - Priority levels: EMERGENCY, ALERT, CRITICAL, ERROR, WARNING, NOTICE, INFO, DEBUG
  - Test rules with falco -r test_rule.yaml -M 10
  - Kubernetes metadata automatically enriched
  - Low overhead — suitable for production workloads

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.