Rule Syntax
Falco rules are the core mechanism for defining what events to monitor and how to detect suspicious behavior in Kubernetes environments. Each rule specifies a pattern of system events (e.g., process executions, file accesses, network connections) and the conditions under which an alert should be triggered. Understanding rule syntax is essential for customizing detection logic, debugging alerts, and integrating Falco with your security workflows.
Rule Structure and Components¶
A Falco rule is composed of several key sections:
- Rule Name: A unique identifier for the rule.
- Description: A human-readable explanation of the rule's purpose.
- Technologies: A list of technologies or components the rule applies to (e.g.,
k8s,container,process). - Condition: A boolean expression that defines the logic for matching events.
- Output: The message displayed when the rule triggers an alert.
Example rule:
rule: Unauthorized Container Access
description: Detects unauthorized access to containers by non-root users.
technologies: [k8s, container]
condition: container.image != "trusted/image" and process.args contains "runasroot"
output: "Unauthorized container access detected: %container.image% accessed by %process.args%"
Condition Logic and Event Matching¶
The condition field is the heart of a Falco rule. It uses event fields (e.g., container.image, process.name, file.path) and logical operators (and, or, not) to define matching criteria.
Key Concepts:¶
- Event fields: These are data points extracted from system events (e.g., kernel logs, container metadata).
- Logical operators:
and: All conditions must be true.or: At least one condition must be true.not: Inverts the result of a condition.
Example: Multi-Condition Rule¶
rule: Suspicious Privilege Escalation
description: Detects attempts to escalate privileges via `sudo` in containers.
technologies: [k8s, container]
condition: process.name == "sudo" and container.image contains "malicious-pattern" and process.args contains "root"
output: "Privilege escalation attempt detected: %process.name% executed in %container.image%"
Event Field Matching¶
Falco supports pattern matching via:
- Exact matches: field == "value"
- Substring matches: field contains "substring"
- Negation: field != "value"
For example:
Practical Use Cases¶
-
Detecting Anomalies:
-
Filtering by Container Labels:
Testing and Debugging Rules¶
Use these commands to validate and test rules:
For custom rules, place them in /etc/falco/rules.d/ and restart Falco:
Key takeaways¶
- Falco rules define event patterns and conditions for security alerts.
- Conditions use event fields and logical operators to match specific behaviors.
- Rules can detect anomalies like unauthorized access, privilege escalation, or unexpected network activity.
- Test rules with
falco --testand validate them in production environments. - Customize rules to align with your Kubernetes workload and security policies.