Custom Threat Rules
Falco is designed to detect security threats by analyzing system calls and runtime events. While its built-in rules cover common attack patterns, custom rules are essential for identifying zero-day exploits, insider threats, or novel behaviors that evade standard detection. This section guides you through crafting advanced Falco rules tailored to these scenarios, leveraging event correlation, system call analysis, and contextual filtering.
Understanding Falco Rule Structure¶
Falco rules are defined in YAML files and consist of four core components:
1. Event: The type of event to monitor (e.g., container.start, process.execute).
2. Condition: A logical expression using fields like container.image or process.name.
3. Output: A human-readable message describing the event.
4. Priority: A numerical value (1–100) to determine rule precedence.
Example:
- rule: Suspicious Process Execution
desc: Detects unexpected processes in privileged containers
condition: container.image contains "privileged" and process.name contains "top"
output: "Suspicious process 'top' executed in privileged container"
priority: 80
Crafting Rules for Zero-Day Exploits¶
Zero-day attacks often involve unconventional system calls or behaviors. Use Falco’s syscall field to detect anomalies, such as unexpected memory manipulation or process injection.
Example: Detecting Process Injection
- rule: Process Injection Attempt
desc: Identifies potential process injection via ptrace
condition: syscall.name = "ptrace" and container.image != "gvisor"
output: "Process injection attempt detected via ptrace in container"
priority: 90
ptrace syscall (common in rootkits) outside of known safe containers like gvisor.
Detecting Insider Threats¶
Insider threats often involve access to sensitive data or unauthorized command-line interactions. Use fields like file.path or user.name to filter for suspicious activity.
Example: Unauthorized File Access
- rule: Sensitive Data Exfiltration
desc: Alerts on access to secrets or config files
condition: file.path contains "/secrets/" or file.path contains "/config/" and user.name != "root"
output: "User '{user.name}' accessed sensitive file '{file.path}'"
priority: 75
Advanced Techniques: Event Correlation and Dynamic Rules¶
For complex threats, combine multiple events using logical operators. For example, correlate a container startup with subsequent file access:
- rule: Container + File Access
condition: (container.start and container.image contains "malicious") and (file.access and file.path contains "/etc/passwd")
output: "Container with malicious image accessed critical file"
priority: 95
For dynamic rule loading, use Falco’s API or external tools to inject rules at runtime, enabling adaptive detection based on real-time telemetry.
Testing and Validation¶
Use falco --test to validate rules against predefined test cases. Simulate events with tools like kubectl or socat to ensure rules trigger correctly.
Example: Simulating a Suspicious Process
Key takeaways¶
- Custom Falco rules require precise conditions and prioritization to avoid false positives.
- Focus on system calls (
syscall.name) and contextual fields (file.path,user.name) for advanced threat detection. - Correlate events across multiple rule triggers to identify multi-stage attacks.
- Continuously test and refine rules using Falco’s test framework and real-world scenarios.
- Leverage dynamic rule loading for adaptive, runtime-specific security policies.