Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 34 additions & 0 deletions rules/falco-incubating_rules.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1007,6 +1007,40 @@
# when more than one event type is involved because some event will populate
# the filtercheck and others will always return <NA>. It would be better to use
# a more generic filter like `fs.path.*`
# This rule is focused on detecting shell history deletion, frequently used by unsophisticated adversaries to eliminate evidence.
# Note that it can also trigger when exiting a Terminal shell, such as with `kubectl
# exec`, which may introduce some noise.
- macro: user_known_security_tool_disable_activities
condition: (never_true)

- rule: Defense Tool Disabled or Modified in Container
desc: >
Detect attempts to disable or modify security tooling inside a running container,
including flushing firewall rules via iptables or stopping security daemons such
as falco, auditd, or sysdig. Adversaries impair defenses after achieving initial
execution to operate undetected before lateral movement.
Maps to MITRE ATT&CK T1562.001 (Impair Defenses: Disable or Modify Tools).
condition: >
spawned_process and container
and (
(proc.name in (iptables, ip6tables) and
((proc.args startswith "-F" or proc.args contains " -F") or
proc.args contains "--flush" or
proc.args contains "-X" or proc.args contains "--delete-chain"))
or
(proc.name = systemctl and proc.args startswith "stop " and
(proc.args contains " falco" or proc.args contains " auditd" or
proc.args contains " sysdig" or proc.args contains " osquery"))
or
(proc.name = service and proc.args startswith "stop " and
(proc.args contains " falco" or proc.args contains " auditd"))
)
and not user_known_security_tool_disable_activities
output: Security tool disabled or firewall rules cleared in container | proc=%proc.name args=%proc.args evt_type=%evt.type user=%user.name user_uid=%user.uid user_loginuid=%user.loginuid process=%proc.name proc_exepath=%proc.exepath parent=%proc.pname command=%proc.cmdline terminal=%proc.tty container_id=%container.id image=%container.image.repository
priority:
WARNING
tags: [maturity_incubating, container, process, mitre_defense_evasion, T1562.001]

- rule: Delete or rename shell history
desc: >
Detect shell history deletion, frequently used by unsophisticated adversaries to eliminate evidence.
Expand Down
19 changes: 19 additions & 0 deletions rules/falco_rules.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1263,3 +1263,22 @@
output: Fileless execution via memfd_create | container_start_ts=%container.start_ts proc_cwd=%proc.cwd evt_res=%evt.res proc_sname=%proc.sname gparent=%proc.aname[2] evt_type=%evt.type user=%user.name user_uid=%user.uid user_loginuid=%user.loginuid process=%proc.name proc_exepath=%proc.exepath parent=%proc.pname command=%proc.cmdline terminal=%proc.tty exe_flags=%evt.arg.flags
priority: CRITICAL
tags: [maturity_stable, host, container, process, mitre_defense_evasion, T1620]

# MITRE ATT&CK T1059 — Container Escape via Command Execution
# Detects shell spawned inside container by non-shell parent process
- rule: Detect Shell Spawn in Container (T1059)
desc: >
A shell was spawned inside a container by a process that is not
itself a shell. This is a common indicator of container escape
attempts or command injection exploitation.
condition: >
spawned_process and container and
shell_procs and not proc.pname in (shell_binaries) and
not container.image.repository in (trusted_images)
output: >
Shell spawned in container by non-shell parent
(user=%user.name container=%container.name
parent=%proc.pname shell=%proc.name cmdline=%proc.cmdline
exe_flags=%evt.arg.flags)
priority: WARNING
tags: [container, shell, mitre_execution, T1059]
Loading