FALCO
Runtime security tool for containers and Kubernetes. Detects anomalous behavior using system call monitoring and custom rules.
INSTALLATION#
# Helm (Kubernetes) helm repo add falcosecurity https://falcosecurity.github.io/charts helm install falco falcosecurity/falco --namespace falco --create-namespace # Debian/Ubuntu curl -fsSL https://falco.org/repo/falcosecurity-packages.asc | sudo gpg --dearmor -o /usr/share/keyrings/falco-archive-keyring.gpg sudo apt update && sudo apt install falco # Docker docker run --rm -i -t --privileged \ -v /var/run/docker.sock:/host/var/run/docker.sock \ -v /proc:/host/proc:ro \ falcosecurity/falco
KEY DETECTIONS (DEFAULT RULES)#
- Shell spawned in container - Container running as root - Sensitive file read (/etc/shadow, /etc/passwd) - Network tool launched in container (nmap, curl, wget) - Privilege escalation attempts - Unauthorized process in container - Crypto mining activity - Reverse shell connections - Namespace changes - Kubernetes API access anomalies - Binary written to /tmp or /dev/shm
CUSTOM RULES#
# /etc/falco/falco_rules.local.yaml
- rule: Detect Reverse Shell
desc: Detect reverse shell connections
condition: >
spawned_process and
proc.name in (bash, sh, zsh) and
fd.type = ipv4 and
fd.direction = out
output: >
Reverse shell detected (user=%user.name command=%proc.cmdline
connection=%fd.name container=%container.name)
priority: CRITICAL
tags: [network, shell]
- rule: Detect Kubectl Exec
desc: Detect kubectl exec into pod
condition: >
spawned_process and
container and
proc.pname = runc
output: >
Exec into container (user=%user.name command=%proc.cmdline
container=%container.name pod=%k8s.pod.name)
priority: WARNING
FALCO CONFIGURATION#
# /etc/falco/falco.yaml json_output: true # JSON logs log_level: info stdout_output: enabled: true file_output: enabled: true filename: /var/log/falco/events.log http_output: enabled: true url: http://siem:8080/falco grpc_output: enabled: true
FALCOCTL#
falcoctl driver install # Install kernel driver falcoctl artifact install falco-rules # Update rules falcoctl artifact list # List available artifacts
FALCOSIDEKICK (ALERT ROUTING)#
# Route Falco alerts to: Slack, Teams, Discord, PagerDuty, Elasticsearch, Splunk, Datadog, AWS SNS/SQS/Lambda, GCP Pub/Sub, Kafka, NATS, Webhook # Install with Helm helm install falco falcosecurity/falco \ --set falcosidekick.enabled=true \ --set falcosidekick.config.slack.webhookurl=SLACK_URL
TIPS#
- Default rules cover most container attack patterns - Custom rules use condition/output/priority format - JSON output integrates with SIEM platforms - Falcosidekick routes alerts to 60+ destinations - eBPF driver is preferred over kernel module - Combine with Trivy (build-time) + Falco (runtime) - Priority levels: EMERGENCY, ALERT, CRITICAL, ERROR, WARNING, NOTICE, INFO, DEBUG - Test rules with falco -r test_rule.yaml -M 10 - Kubernetes metadata automatically enriched - Low overhead — suitable for production workloads
FALCO CHEATSHEET
=================
Source: https://cheatsheet.johlem.net
Runtime security tool for containers and Kubernetes. Detects
anomalous behavior using system call monitoring and custom rules.
INSTALLATION
-------------
# Helm (Kubernetes)
helm repo add falcosecurity https://falcosecurity.github.io/charts
helm install falco falcosecurity/falco --namespace falco --create-namespace
# Debian/Ubuntu
curl -fsSL https://falco.org/repo/falcosecurity-packages.asc | sudo gpg --dearmor -o /usr/share/keyrings/falco-archive-keyring.gpg
sudo apt update && sudo apt install falco
# Docker
docker run --rm -i -t --privileged \
-v /var/run/docker.sock:/host/var/run/docker.sock \
-v /proc:/host/proc:ro \
falcosecurity/falco
KEY DETECTIONS (DEFAULT RULES)
---------------------------------
- Shell spawned in container
- Container running as root
- Sensitive file read (/etc/shadow, /etc/passwd)
- Network tool launched in container (nmap, curl, wget)
- Privilege escalation attempts
- Unauthorized process in container
- Crypto mining activity
- Reverse shell connections
- Namespace changes
- Kubernetes API access anomalies
- Binary written to /tmp or /dev/shm
CUSTOM RULES
--------------
# /etc/falco/falco_rules.local.yaml
- rule: Detect Reverse Shell
desc: Detect reverse shell connections
condition: >
spawned_process and
proc.name in (bash, sh, zsh) and
fd.type = ipv4 and
fd.direction = out
output: >
Reverse shell detected (user=%user.name command=%proc.cmdline
connection=%fd.name container=%container.name)
priority: CRITICAL
tags: [network, shell]
- rule: Detect Kubectl Exec
desc: Detect kubectl exec into pod
condition: >
spawned_process and
container and
proc.pname = runc
output: >
Exec into container (user=%user.name command=%proc.cmdline
container=%container.name pod=%k8s.pod.name)
priority: WARNING
FALCO CONFIGURATION
---------------------
# /etc/falco/falco.yaml
json_output: true # JSON logs
log_level: info
stdout_output:
enabled: true
file_output:
enabled: true
filename: /var/log/falco/events.log
http_output:
enabled: true
url: http://siem:8080/falco
grpc_output:
enabled: true
FALCOCTL
---------
falcoctl driver install # Install kernel driver
falcoctl artifact install falco-rules # Update rules
falcoctl artifact list # List available artifacts
FALCOSIDEKICK (ALERT ROUTING)
--------------------------------
# Route Falco alerts to:
Slack, Teams, Discord, PagerDuty,
Elasticsearch, Splunk, Datadog,
AWS SNS/SQS/Lambda, GCP Pub/Sub,
Kafka, NATS, Webhook
# Install with Helm
helm install falco falcosecurity/falco \
--set falcosidekick.enabled=true \
--set falcosidekick.config.slack.webhookurl=SLACK_URL
TIPS
-----
- Default rules cover most container attack patterns
- Custom rules use condition/output/priority format
- JSON output integrates with SIEM platforms
- Falcosidekick routes alerts to 60+ destinations
- eBPF driver is preferred over kernel module
- Combine with Trivy (build-time) + Falco (runtime)
- Priority levels: EMERGENCY, ALERT, CRITICAL, ERROR, WARNING, NOTICE, INFO, DEBUG
- Test rules with falco -r test_rule.yaml -M 10
- Kubernetes metadata automatically enriched
- Low overhead — suitable for production workloads
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.