Skip to content

Custom Threat Rules

Falco is designed to detect security threats by analyzing system calls and runtime events. While its built-in rules cover common attack patterns, custom rules are essential for identifying zero-day exploits, insider threats, or novel behaviors that evade standard detection. This section guides you through crafting advanced Falco rules tailored to these scenarios, leveraging event correlation, system call analysis, and contextual filtering.


Understanding Falco Rule Structure

Falco rules are defined in YAML files and consist of four core components:
1. Event: The type of event to monitor (e.g., container.start, process.execute).
2. Condition: A logical expression using fields like container.image or process.name.
3. Output: A human-readable message describing the event.
4. Priority: A numerical value (1–100) to determine rule precedence.

Example:

- rule: Suspicious Process Execution
  desc: Detects unexpected processes in privileged containers
  condition: container.image contains "privileged" and process.name contains "top"
  output: "Suspicious process 'top' executed in privileged container"
  priority: 80


Crafting Rules for Zero-Day Exploits

Zero-day attacks often involve unconventional system calls or behaviors. Use Falco’s syscall field to detect anomalies, such as unexpected memory manipulation or process injection.

Example: Detecting Process Injection

- rule: Process Injection Attempt
  desc: Identifies potential process injection via ptrace
  condition: syscall.name = "ptrace" and container.image != "gvisor"
  output: "Process injection attempt detected via ptrace in container"
  priority: 90
This rule flags use of the ptrace syscall (common in rootkits) outside of known safe containers like gvisor.


Detecting Insider Threats

Insider threats often involve access to sensitive data or unauthorized command-line interactions. Use fields like file.path or user.name to filter for suspicious activity.

Example: Unauthorized File Access

- rule: Sensitive Data Exfiltration
  desc: Alerts on access to secrets or config files
  condition: file.path contains "/secrets/" or file.path contains "/config/" and user.name != "root"
  output: "User '{user.name}' accessed sensitive file '{file.path}'"
  priority: 75
This rule flags access to sensitive paths by non-root users, which could indicate data exfiltration.


Advanced Techniques: Event Correlation and Dynamic Rules

For complex threats, combine multiple events using logical operators. For example, correlate a container startup with subsequent file access:

- rule: Container + File Access
  condition: (container.start and container.image contains "malicious") and (file.access and file.path contains "/etc/passwd")
  output: "Container with malicious image accessed critical file"
  priority: 95

For dynamic rule loading, use Falco’s API or external tools to inject rules at runtime, enabling adaptive detection based on real-time telemetry.


Testing and Validation

Use falco --test to validate rules against predefined test cases. Simulate events with tools like kubectl or socat to ensure rules trigger correctly.

Example: Simulating a Suspicious Process

kubectl run -it --rm --image=alpine test-shell
Monitor the pod’s activity with Falco to verify rule detection.


Key takeaways

  • Custom Falco rules require precise conditions and prioritization to avoid false positives.
  • Focus on system calls (syscall.name) and contextual fields (file.path, user.name) for advanced threat detection.
  • Correlate events across multiple rule triggers to identify multi-stage attacks.
  • Continuously test and refine rules using Falco’s test framework and real-world scenarios.
  • Leverage dynamic rule loading for adaptive, runtime-specific security policies.