Skip to content

Detection Policies

Falco uses syscall-based detection policies to monitor low-level kernel events and identify suspicious behavior in Kubernetes workloads. By defining custom rules that target specific syscalls, you can create fine-grained security policies tailored to your environment. This section demonstrates how to configure Falco to monitor syscalls for runtime security events.


Defining Syscall Rules in Falco

Falco policies are defined in the falco.yaml configuration file (typically located at /etc/falco/falco.yaml). Rules are structured using the rules section, where each rule specifies a syscall, conditions, and alerting logic.

Example: Monitoring File Access

- rule: Unauthorized File Access
  desc: Detect attempts to read sensitive files
  condition: (open.filename contains "/etc/passwd") and (open.flags contains "O_RDONLY")
  output: "Process {{ pid }} ({{ comm }}) attempted to read {{ open.filename }}"
  priority: medium
  tags: [k8s, file]

This rule triggers when a process opens /etc/passwd in read-only mode, which could indicate reconnaissance activity.


Enabling Kubernetes Context in Rules

Falco can integrate with Kubernetes to filter events based on pod metadata. Use the k8s.pod.namespace and k8s.pod.name fields to scope alerts to specific workloads:

- rule: Suspicious Exec in Production Namespace
  condition: (execve.filename contains "/usr/bin/curl") and (k8s.pod.namespace = "production")
  output: "Pod {{ k8s.pod.name }} executed {{ execve.filename }} in production namespace"
  priority: high
  tags: [k8s, network]

To enable Kubernetes context, start Falco with the --k8s-apiserver flag and ensure it runs as a privileged container or with appropriate SELinux/AppArmor policies.


Testing and Validating Rules

After configuring rules, test them by simulating events:

# Simulate a file read (requires root privileges)
sudo dd if=/etc/passwd of=/tmp/test.txt

Verify Falco alerts:

sudo falco --test

Use falco --help to explore additional testing options, such as replaying audit logs or simulating syscalls.


Key Takeaways

  • Define rules using condition to target specific syscalls and contextual metadata.
  • Leverage Kubernetes fields like k8s.pod.namespace to scope alerts to workloads.
  • Test rules with falco --test to ensure they trigger expected alerts.
  • Adjust priorities and tags to align with your organization's security policies.