What it does. Writes and tunes Falco rule syntax for container escape detection - conditions, macros, lists, priorities, and output fields - covering host filesystem mounts, sensitive host path access, kernel module loading, and privileged capability abuse, including how to drive down false positives. Use when authoring or tuning a specific Falco rule for breakout behaviour, or triaging a noisy escape-related Falco alert. Keywords: Falco rule, macro, list, condition, priority, falco_rules.local.yaml, tuning, false positive. Do not use for deploying and operating Falco itself - use detecting-container-runtime-threats-with-falco; for tool-agnostic escape signals use detecting-container-escape-attempts. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-container-escape-with-falco-rules, or copy the skill folder into ~/.claude/skills/detecting-container-escape-with-falco-rules/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-container-escape-with-falco-rules/SKILL.md
SKILL.md (verbatim)
name: detecting-container-escape-with-falco-rules
description: >-
Writes and tunes Falco rule syntax for container escape detection - conditions, macros,
lists, priorities, and output fields - covering host filesystem mounts, sensitive host path
access, kernel module loading, and privileged capability abuse, including how to drive down
false positives. Use when authoring or tuning a specific Falco rule for breakout behaviour,
or triaging a noisy escape-related Falco alert. Keywords: Falco rule, macro, list,
condition, priority, falco_rules.local.yaml, tuning, false positive. Do not use for
deploying and operating Falco itself - use detecting-container-runtime-threats-with-falco;
for tool-agnostic escape signals use detecting-container-escape-attempts.
domain: cybersecurity
subdomain: container-security
tags:
- falco
- container-escape
- runtime-security
- syscall-monitoring
- kubernetes
- detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Token Binding
- Execution Isolation
- File Metadata Consistency Validation
- Restore Access
- Application Protocol Command Analysis
nist_csf:
- PR.PS-01
- PR.IR-01
- ID.AM-08
- DE.CM-01
mitre_attack:
- T1610
- T1611
- T1609
- T1525
- T1068
Detecting Container Escape with Falco Rules
Overview
Falco is a CNCF-graduated runtime security tool that monitors Linux syscalls to detect anomalous container behavior. It uses a rules engine to identify container escape techniques such as mounting host filesystems, accessing sensitive host paths, loading kernel modules, and exploiting privileged container capabilities.
When to Use
- When investigating security incidents that require detecting container escape with falco rules
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques
Prerequisites
- Linux host with kernel 5.8+ (for eBPF driver) or kernel module support
- Kubernetes cluster (v1.24+) or standalone Docker/containerd
- Helm 3 for Kubernetes deployment
- Root or privileged access for driver installation
Installing Falco
Kubernetes Deployment with Helm
# Add Falco Helm chart
helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update
# Install Falco with eBPF driver
helm install falco falcosecurity/falco \
--namespace falco --create-namespace \
--set falcosidekick.enabled=true \
--set falcosidekick.webui.enabled=true \
--set driver.kind=ebpf \
--set collectors.containerd.enabled=true \
--set collectors.containerd.socket=/run/containerd/containerd.sock
# Verify
kubectl get pods -n falco
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=20
Standalone Installation (Debian/Ubuntu)
# Add Falco GPG key and repo
curl -fsSL https://falco.org/repo/falcosecurity-packages.asc | \
sudo gpg --dearmor -o /usr/share/keyrings/falco-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/falco-archive-keyring.gpg] https://download.falco.org/packages/deb stable main" | \
sudo tee /etc/apt/sources.list.d/falcosecurity.list
sudo apt-get update
sudo apt-get install -y falco
# Start Falco
sudo systemctl enable falco
sudo systemctl start falco
Container Escape Detection Rules
Rule 1: Detect Host Mount from Container
- rule: Container Mounting Host Filesystem
desc: Detect a container attempting to mount the host filesystem
condition: >
spawned_process and container and
proc.name = mount and
(proc.args contains "/host" or proc.args contains "nsenter")
output: >
Container mounting host filesystem
(user=%user.name container_id=%container.id container_name=%container.name
image=%container.image.repository command=%proc.cmdline %evt.args)
priority: CRITICAL
tags: [container, escape, T1611]
Rule 2: Detect nsenter Usage (Namespace Escape)
- rule: Nsenter Execution in Container
desc: Detect nsenter being used to escape container namespaces
condition: >
spawned_process and container and proc.name = nsenter
output: >
nsenter executed in container - potential escape attempt
(user=%user.name container_id=%container.id image=%container.image.repository
command=%proc.cmdline parent=%proc.pname)
priority: CRITICAL
tags: [container, escape, namespace, T1611]
Rule 3: Detect Privileged Container Launch
- rule: Launch Privileged Container
desc: Detect a privileged container being launched
condition: >
container_started and container and container.privileged=true
output: >
Privileged container started
(user=%user.name container_id=%container.id container_name=%container.name
image=%container.image.repository)
priority: WARNING
tags: [container, privileged, T1610]
Rule 4: Detect /proc/sysrq-trigger Write
- rule: Write to Sysrq Trigger
desc: Detect writes to /proc/sysrq-trigger which can crash or control the host
condition: >
open_write and container and fd.name = /proc/sysrq-trigger
output: >
Write to /proc/sysrq-trigger from container
(user=%user.name container_id=%container.id image=%container.image.repository
command=%proc.cmdline)
priority: CRITICAL
tags: [container, escape, host-manipulation]
Rule 5: Detect Kernel Module Loading from Container
- rule: Container Loading Kernel Module
desc: Detect a container attempting to load a kernel module
condition: >
spawned_process and container and
(proc.name in (insmod, modprobe) or
(proc.name = init_module))
output: >
Kernel module loading from container
(user=%user.name container_id=%container.id image=%container.image.repository
command=%proc.cmdline)
priority: CRITICAL
tags: [container, escape, kernel, T1611]
Rule 6: Detect Container Breakout via cgroups
- rule: Write to Cgroup Release Agent
desc: Detect writes to cgroup release_agent which is a known container escape vector
condition: >
open_write and container and
fd.name endswith release_agent
output: >
Container writing to cgroup release_agent - escape attempt
(user=%user.name container_id=%container.id image=%container.image.repository
file=%fd.name command=%proc.cmdline)
priority: CRITICAL
tags: [container, escape, cgroup, CVE-2022-0492]
Rule 7: Detect Access to Host /etc/shadow
- rule: Container Reading Host Shadow File
desc: Detect a container reading /etc/shadow on the host via mounted volume
condition: >
open_read and container and
(fd.name = /etc/shadow or fd.name startswith /host/etc/shadow)
output: >
Container reading host shadow file
(user=%user.name container_id=%container.id image=%container.image.repository
file=%fd.name command=%proc.cmdline)
priority: CRITICAL
tags: [container, credential-access, T1003]
Rule 8: Detect Docker Socket Access
- rule: Container Accessing Docker Socket
desc: Detect a container accessing the Docker socket which allows host control
condition: >
(open_read or open_write) and container and
fd.name = /var/run/docker.sock
output: >
Container accessing Docker socket
(user=%user.name container_id=%container.id image=%container.image.repository
command=%proc.cmdline)
priority: CRITICAL
tags: [container, escape, docker-socket, T1610]
Complete Custom Rules File
# /etc/falco/rules.d/container-escape.yaml
- list: escape_binaries
items: [nsenter, chroot, unshare, mount, umount, pivot_root]
- macro: container_escape_attempt
condition: >
spawned_process and container and
proc.name in (escape_binaries)
- rule: Container Escape Binary Execution
desc: Detect execution of binaries commonly used for container escape
condition: container_escape_attempt
output: >
Escape-related binary executed in container
(user=%user.name container=%container.name image=%container.image.repository
command=%proc.cmdline parent=%proc.pname pid=%proc.pid)
priority: CRITICAL
tags: [container, escape, mitre_T1611]
- rule: Sensitive File Access from Container
desc: Detect container access to sensitive host files
condition: >
(open_read or open_write) and container and
(fd.name startswith /proc/1/ or
fd.name = /etc/shadow or
fd.name = /etc/kubernetes/admin.conf or
fd.name startswith /var/lib/kubelet/)
output: >
Sensitive file accessed from container
(container=%container.name image=%container.image.repository
file=%fd.name command=%proc.cmdline user=%user.name)
priority: CRITICAL
tags: [container, sensitive-file, mitre_T1005]
Falco Configuration
# /etc/falco/falco.yaml (key settings)
rules_files:
- /etc/falco/falco_rules.yaml
- /etc/falco/rules.d/container-escape.yaml
json_output: true
json_include_output_property: true
json_include_tags_property: true
log_stderr: true
log_syslog: true
log_level: info
priority: WARNING
stdout_output:
enabled: true
syslog_output:
enabled: true
http_output:
enabled: true
url: http://falcosidekick:2801
insecure: true
grpc:
enabled: true
bind_address: "unix:///run/falco/falco.sock"
threadiness: 8
grpc_output:
enabled: true
Alert Integration
Forward to Slack via Falcosidekick
# Falcosidekick values.yaml
config:
slack:
webhookurl: "https://hooks.slack.com/services/XXXXX"
minimumpriority: "warning"
messageformat: |
*{{.Priority}}* - {{.Rule}}
Container: {{.OutputFields.container_name}}
Image: {{.OutputFields.container_image_repository}}
Command: {{.OutputFields.proc_cmdline}}
Testing Rules
# Simulate container escape attempt (in a test container)
kubectl run test-escape --image=alpine --restart=Never -- sh -c "cat /etc/shadow"
# Simulate nsenter
kubectl run test-nsenter --image=alpine --restart=Never --overrides='{"spec":{"hostPID":true}}' -- nsenter -t 1 -m -u -i -n -- cat /etc/hostname
# Check Falco alerts
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=50 | grep -i escape
Best Practices
- Deploy Falco as DaemonSet to ensure coverage on all nodes
- Use eBPF driver over kernel module for safer operation
- Start with default rules (maturity_stable) then add custom rules
- Forward alerts to SIEM/SOAR via Falcosidekick
- Tag rules with MITRE ATT&CK technique IDs for correlation
- Test rules in permissive mode before enforcing
- Tune false positives by adding exception lists for known good processes
- Monitor Falco health with Prometheus metrics endpoint
Other files in this skill
assets/template.md (verbatim)
Falco Container Escape Detection Runbook
Alert Triage Template
Alert Details
| Field |
Value |
| Alert Time |
|
| Rule Name |
|
| Priority |
|
| Container Name |
|
| Container Image |
|
| Pod Name |
|
| Namespace |
|
| Node |
|
| User |
|
| Process Command |
|
| MITRE Technique |
|
Triage Steps
Investigation (5-30 minutes)
Containment (if confirmed)
Recovery
False Positive Exceptions
| Container Image |
Rule |
Justification |
Approved By |
Date |
|
|
|
|
|
Escalation Matrix
| Priority |
Response Time |
Notify |
| CRITICAL |
Immediate |
Security On-Call + Engineering Lead |
| WARNING |
15 minutes |
Security On-Call |
| NOTICE |
1 hour |
Security Team queue |
| INFO |
Next business day |
Review in daily standup |
references/api-reference.md (verbatim)
API Reference: Detecting Container Escape with Falco Rules
Falco CLI
falco --version # check version
falco --validate /path/to/rules.yaml # validate rules syntax
falco -r /etc/falco/rules.d/escape.yaml # load specific rules
falco --list # list all available fields
falco --list-events # list supported syscalls
Falco Rule Syntax
- rule: <name>
desc: <description>
condition: <filter expression>
output: <alert message with fields>
priority: <Emergency|Alert|Critical|Error|Warning|Notice|Informational|Debug>
tags: [tag1, tag2]
enabled: true
Key Falco Filter Fields
| Field |
Description |
container |
True if event is from a container |
spawned_process |
True if new process spawned |
proc.name |
Process name |
proc.cmdline |
Full command line |
proc.pname |
Parent process name |
fd.name |
File descriptor name/path |
container.name |
Container name |
container.image.repository |
Image repository |
container.privileged |
True if privileged |
proc.is_exe_upper_layer |
Binary not in original image |
evt.type |
Syscall type (setns, unshare, mount) |
{
"time": "2024-01-15T10:30:00.000Z",
"rule": "Container Escape Binary Execution",
"priority": "Critical",
"source": "syscall",
"output": "Escape binary in container...",
"output_fields": {
"user.name": "root",
"proc.cmdline": "nsenter -t 1 -m -u -i -n",
"container.name": "attacker-pod"
},
"tags": ["container", "escape", "T1611"]
}
Falcosidekick Alert Routing
config:
slack:
webhookurl: "https://hooks.slack.com/services/XXX"
minimumpriority: "critical"
elasticsearch:
hostport: "https://es:9200"
index: "falco-alerts"
Helm Deployment
helm repo add falcosecurity https://falcosecurity.github.io/charts
helm install falco falcosecurity/falco \
--namespace falco --create-namespace \
--set driver.kind=ebpf \
--set falcosidekick.enabled=true
CLI Usage
python agent.py --check-status
python agent.py --validate-rules /etc/falco/rules.d/escape.yaml
python agent.py --parse-alerts /var/log/falco/events.json --min-priority Warning
python agent.py --generate-rules > escape-rules.yaml
references/standards.md (verbatim)
Standards and References - Container Escape Detection with Falco
Industry Standards
NIST SP 800-190: Application Container Security Guide
- Section 4.3: Container Runtime - Monitor containers for anomalous behavior at runtime
- Section 5.4: Container Runtime Security - Implement runtime monitoring and alerting
- Recommends syscall-level monitoring for escape detection
CIS Kubernetes Benchmark v1.8
- 5.7.1: Create administrative boundaries between resources using namespaces
- 5.7.2: Ensure that the seccomp profile is set to docker/default
- 5.7.3: Apply Security Context to pods and containers
- 5.7.4: The default namespace should not be used
MITRE ATT&CK for Containers
| Technique ID |
Name |
Falco Detection |
| T1611 |
Escape to Host |
nsenter, mount, chroot detection |
| T1610 |
Deploy Container |
Privileged container launch detection |
| T1003 |
OS Credential Dumping |
/etc/shadow access from container |
| T1005 |
Data from Local System |
Sensitive file read detection |
| T1059 |
Command and Scripting Interpreter |
Shell spawn in container |
| T1068 |
Exploitation for Privilege Escalation |
Kernel exploit indicators |
NSA/CISA Kubernetes Hardening Guide v1.2
- Section 5: Audit Logging and Threat Detection
- Enable runtime security monitoring
- Detect anomalous container behavior in real-time
- Monitor for privilege escalation attempts
Falco Rule Maturity Levels
| Level |
Description |
Count |
| maturity_stable |
Production-ready, low false positives |
25 rules |
| maturity_incubating |
Proven useful, may need tuning |
~30 rules |
| maturity_sandbox |
Experimental, high false positive rate |
~38 rules |
| maturity_deprecated |
Scheduled for removal |
Variable |
Known Container Escape CVEs
| CVE |
Description |
Falco Rule |
| CVE-2024-21626 |
runc process.cwd container breakout |
Detect use of /proc/self/fd to access host |
| CVE-2022-0492 |
cgroup v1 release_agent escape |
Write to Cgroup Release Agent |
| CVE-2022-0185 |
File system context exploit |
Detect unshare in container |
| CVE-2020-15257 |
containerd-shim API access |
Detect abstract socket connections |
| CVE-2019-5736 |
runc overwrite host binary |
Detect writes to /proc/self/exe |
Compliance Mappings
PCI DSS v4.0
- Requirement 10.6.1: Review logs for anomalies at least daily
- Requirement 11.5: Deploy change-detection mechanisms
SOC 2 Type II
- CC7.2: Monitor system components for anomalies
- CC7.3: Evaluate security events to determine impact
references/workflows.md (verbatim)
Workflow - Detecting Container Escape with Falco Rules
Phase 1: Deploy Falco
Install on Kubernetes
helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update
helm install falco falcosecurity/falco \
--namespace falco --create-namespace \
--set driver.kind=ebpf \
--set falcosidekick.enabled=true \
--set falcosidekick.webui.enabled=true \
--set collectors.containerd.enabled=true
kubectl -n falco rollout status daemonset/falco --timeout=120s
Verify Deployment
kubectl get pods -n falco -o wide
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=10
Phase 2: Deploy Custom Escape Detection Rules
Create ConfigMap with Custom Rules
kubectl create configmap falco-escape-rules -n falco \
--from-file=container-escape.yaml=/path/to/container-escape.yaml
# Restart Falco to load new rules
kubectl rollout restart daemonset/falco -n falco
Validate Rules Loaded
kubectl exec -n falco $(kubectl get pod -n falco -l app.kubernetes.io/name=falco -o jsonpath='{.items[0].metadata.name}') -- \
falco --list | grep -i escape
Phase 3: Test Detection
Test 1 - Privileged Container
kubectl run escape-test-priv --image=alpine --restart=Never \
--overrides='{"spec":{"containers":[{"name":"test","image":"alpine","command":["sleep","30"],"securityContext":{"privileged":true}}]}}'
# Check alert
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=5 | grep -i privileged
kubectl delete pod escape-test-priv
Test 2 - Sensitive File Access
kubectl run escape-test-shadow --image=alpine --restart=Never -- cat /etc/shadow
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=5 | grep -i shadow
kubectl delete pod escape-test-shadow
Test 3 - Shell Spawn
kubectl exec -it deploy/some-app -- /bin/sh
# In Falco logs, should see "Terminal shell in container"
Phase 4: Integrate Alerting
# values-sidekick.yaml
config:
slack:
webhookurl: "https://hooks.slack.com/services/XXX/YYY/ZZZ"
minimumpriority: "warning"
elasticsearch:
hostport: "https://elasticsearch:9200"
index: "falco"
minimumpriority: "notice"
prometheus:
enabled: true
helm upgrade falco falcosecurity/falco -n falco \
-f values-sidekick.yaml
Phase 5: Tune and Maintain
Handle False Positives
# Add exceptions to rules
- rule: Terminal shell in container
append: true
exceptions:
- name: known_shell_spawners
fields: [container.image.repository]
comps: [in]
values:
- [my-debug-image, kubectl-debug]
Regular Maintenance
- Update Falco rules weekly:
falcoctl artifact install falco-rules
- Review new maturity_stable rules after each Falco release
- Correlate Falco alerts with Kubernetes audit logs
- Run escape simulation exercises monthly
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.