Skip to content

Rule Syntax

Falco rules are the core mechanism for defining what events to monitor and how to detect suspicious behavior in Kubernetes environments. Each rule specifies a pattern of system events (e.g., process executions, file accesses, network connections) and the conditions under which an alert should be triggered. Understanding rule syntax is essential for customizing detection logic, debugging alerts, and integrating Falco with your security workflows.


Rule Structure and Components

A Falco rule is composed of several key sections:

  1. Rule Name: A unique identifier for the rule.
  2. Description: A human-readable explanation of the rule's purpose.
  3. Technologies: A list of technologies or components the rule applies to (e.g., k8s, container, process).
  4. Condition: A boolean expression that defines the logic for matching events.
  5. Output: The message displayed when the rule triggers an alert.

Example rule:

rule: Unauthorized Container Access
description: Detects unauthorized access to containers by non-root users.
technologies: [k8s, container]
condition: container.image != "trusted/image" and process.args contains "runasroot"
output: "Unauthorized container access detected: %container.image% accessed by %process.args%"


Condition Logic and Event Matching

The condition field is the heart of a Falco rule. It uses event fields (e.g., container.image, process.name, file.path) and logical operators (and, or, not) to define matching criteria.

Key Concepts:

  • Event fields: These are data points extracted from system events (e.g., kernel logs, container metadata).
  • Logical operators:
  • and: All conditions must be true.
  • or: At least one condition must be true.
  • not: Inverts the result of a condition.

Example: Multi-Condition Rule

rule: Suspicious Privilege Escalation
description: Detects attempts to escalate privileges via `sudo` in containers.
technologies: [k8s, container]
condition: process.name == "sudo" and container.image contains "malicious-pattern" and process.args contains "root"
output: "Privilege escalation attempt detected: %process.name% executed in %container.image%"

Event Field Matching

Falco supports pattern matching via:
- Exact matches: field == "value"
- Substring matches: field contains "substring"
- Negation: field != "value"

For example:

condition: file.path contains "/etc/passwd" and file.action == "write"


Practical Use Cases

  1. Detecting Anomalies:

    rule: Unexpected Network Connection
    condition: network.direction == "out" and network.destination != "10.0.0.0/8"
    output: "Unexpected outbound network connection: %network.destination%"
    

  2. Filtering by Container Labels:

    rule: Unlabeled Critical Pod
    condition: container.label does not contain "app=production"
    output: "Critical pod without label: %container.name%"
    


Testing and Debugging Rules

Use these commands to validate and test rules:

# List all built-in rules
falco --list-rules

# Test a rule against simulated events
falco --test

For custom rules, place them in /etc/falco/rules.d/ and restart Falco:

sudo systemctl restart falco


Key takeaways

  • Falco rules define event patterns and conditions for security alerts.
  • Conditions use event fields and logical operators to match specific behaviors.
  • Rules can detect anomalies like unauthorized access, privilege escalation, or unexpected network activity.
  • Test rules with falco --test and validate them in production environments.
  • Customize rules to align with your Kubernetes workload and security policies.