Skip to content

Syscall Monitoring

Falco is a lightweight, open-source runtime security tool that leverages Linux syscalls to monitor and detect suspicious behavior in containerized applications. By intercepting low-level interactions between processes and the Linux kernel, Falco provides real-time visibility into system calls (syscalls) executed by containers, enabling the identification of potential security threats such as unauthorized file access, unexpected network connections, or privilege escalation attempts. This section explains how Falco uses syscall monitoring to enforce runtime security in Kubernetes environments.


Understanding Linux Syscalls in Container Environments

A syscall (system call) is a mechanism that allows user-space processes to request services from the Linux kernel. In containerized workloads, syscalls are critical for operations like file I/O, process execution, and network communication. Each syscall represents a potential entry point for malicious activity, making them a prime target for runtime security monitoring.

In containers, syscalls are executed in isolated namespaces and cgroups, but the kernel still tracks them. Falco captures these syscalls using eBPF (Extended Berkeley Packet Filter), a programmable framework that allows safe, high-performance monitoring of kernel events without modifying the kernel source code. This enables Falco to inspect syscalls in real time with minimal performance overhead.


How Falco Monitors Syscalls

Falco uses eBPF to deploy tracepoints and kprobes that capture syscall events. These events are then analyzed by Falco’s rule engine, which compares them against predefined rules to detect anomalies. For example:

  • A container attempting to read /etc/shadow (a file containing password hashes) might trigger a rule that flags this as a potential credential theft attempt.
  • A process spawning a new executable with elevated privileges could be flagged as a privilege escalation risk.

Falco’s rules are written in a simple, human-readable format and can be customized to match specific security policies. The tool supports both eBPF-based and legacy (LSM) rules, though eBPF is recommended for modern Kubernetes environments due to its lower overhead and broader syscall coverage.


Detecting Suspicious Behavior with Falco

Falco’s syscall monitoring is particularly effective for detecting container escape attempts, data exfiltration, and unauthorized process execution. Here are some common use cases:

1. File Access Monitoring

Falco can detect when a container accesses sensitive files, such as /etc/passwd or /root/.ssh/id_rsa. For example:

- rule: Unauthorized File Access
  desc: A process is accessing a file that is not allowed.
  condition: > 
    (file.name contains "/etc/passwd" or file.name contains "/root/.ssh/id_rsa") 
    and (evt.type is file_access)
  output: Process {{ pid }} ({{ comm }}) accessed {{ file.name }}.
  priority: medium
  tags: file, sensitive

2. Network Connection Monitoring

Falco can flag connections to unexpected IP addresses or ports. For instance:

- rule: Unexpected Network Connection
  desc: A container is connecting to an external IP that is not whitelisted.
  condition: > 
    (network.direction is out) 
    and (network.ip is not in [10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16])
  output: Process {{ pid }} ({{ comm }}) connected to {{ network.ip }}.
  priority: high
  tags: network, external

3. Process Execution Monitoring

Falco can detect when a container spawns new processes, which may indicate malware or privilege escalation:

- rule: Suspicious Process Execution
  desc: A container is executing a process with elevated privileges.
  condition: > 
    (evt.type is process_exec) 
    and (proc.credential.euid != 0) 
    and (proc.name contains "sudo" or proc.name contains "su")
  output: Process {{ pid }} ({{ comm }}) executed {{ proc.name }} with elevated privileges.
  priority: critical
  tags: process, escalation


Practical Example: Enabling Syscall Monitoring

To monitor syscalls in a Kubernetes cluster, install Falco and configure it to use eBPF:

# Install Falco using Helm (example for Kubernetes)
helm repo add falco https://falco.org/helm/charts
helm install falco falco/falco --set config.useEBAF=true

Once running, Falco streams alerts to stdout or a logging system. To verify syscall monitoring is active:

kubectl logs <falco-pod-name>

Look for events like:

A process (pid=123) executed /bin/sh with elevated privileges.


Key takeaways

  • Falco uses Linux syscalls and eBPF to monitor container behavior at the kernel level.
  • Syscall monitoring enables detection of file access, network connections, and process execution anomalies.
  • Falco’s rule-based engine allows customization to align with specific security policies.
  • eBPF-based monitoring provides low-overhead, high-fidelity visibility into container runtime activities.