detecting-container-escape-with-falco-rules skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki
Contents
  1. Install
  2. SKILL.md (verbatim)
  3. Overview
  4. When to Use
  5. Prerequisites
  6. Installing Falco
  7. Kubernetes Deployment with Helm
  8. Standalone Installation (Debian/Ubuntu)
  9. Container Escape Detection Rules
  10. Rule 1: Detect Host Mount from Container
  11. Rule 2: Detect nsenter Usage (Namespace Escape)
  12. Rule 3: Detect Privileged Container Launch
  13. Rule 4: Detect /proc/sysrq-trigger Write
  14. Rule 5: Detect Kernel Module Loading from Container
  15. Rule 6: Detect Container Breakout via cgroups
  16. Rule 7: Detect Access to Host /etc/shadow
  17. Rule 8: Detect Docker Socket Access
  18. Complete Custom Rules File
  19. Falco Configuration
  20. Alert Integration
  21. Forward to Slack via Falcosidekick
  22. Testing Rules
  23. Best Practices
  24. Other files in this skill
  25. assets/template.md (verbatim)
  26. Alert Triage Template
  27. Alert Details
  28. Triage Steps
  29. Immediate Actions (0-5 minutes)
  30. Investigation (5-30 minutes)
  31. Containment (if confirmed)
  32. Recovery
  33. False Positive Exceptions
  34. Escalation Matrix
  35. references/api-reference.md (verbatim)
  36. Falco CLI
  37. Falco Rule Syntax
  38. Key Falco Filter Fields
  39. Falco JSON Output Format
  40. Falcosidekick Alert Routing
  41. Helm Deployment
  42. CLI Usage
  43. references/standards.md (verbatim)
  44. Industry Standards
  45. NIST SP 800-190: Application Container Security Guide
  46. CIS Kubernetes Benchmark v1.8
  47. MITRE ATT&CK for Containers
  48. NSA/CISA Kubernetes Hardening Guide v1.2
  49. Falco Rule Maturity Levels
  50. Known Container Escape CVEs
  51. Compliance Mappings
  52. PCI DSS v4.0
  53. SOC 2 Type II
  54. references/workflows.md (verbatim)
  55. Phase 1: Deploy Falco
  56. Install on Kubernetes
  57. Verify Deployment
  58. Phase 2: Deploy Custom Escape Detection Rules
  59. Create ConfigMap with Custom Rules
  60. Validate Rules Loaded
  61. Phase 3: Test Detection
  62. Test 1 - Privileged Container
  63. Test 2 - Sensitive File Access
  64. Test 3 - Shell Spawn
  65. Phase 4: Integrate Alerting
  66. Configure Falcosidekick Outputs
  67. Phase 5: Tune and Maintain
  68. Handle False Positives
  69. Regular Maintenance

What it does. Writes and tunes Falco rule syntax for container escape detection - conditions, macros, lists, priorities, and output fields - covering host filesystem mounts, sensitive host path access, kernel module loading, and privileged capability abuse, including how to drive down false positives. Use when authoring or tuning a specific Falco rule for breakout behaviour, or triaging a noisy escape-related Falco alert. Keywords: Falco rule, macro, list, condition, priority, falco_rules.local.yaml, tuning, false positive. Do not use for deploying and operating Falco itself - use detecting-container-runtime-threats-with-falco; for tool-agnostic escape signals use detecting-container-escape-attempts. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/detecting-container-escape-with-falco-rules/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-container-escape-with-falco-rules, or copy the skill folder into ~/.claude/skills/detecting-container-escape-with-falco-rules/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-container-escape-with-falco-rules/SKILL.md

SKILL.md (verbatim)

name: detecting-container-escape-with-falco-rules
description: >-
  Writes and tunes Falco rule syntax for container escape detection - conditions, macros,
  lists, priorities, and output fields - covering host filesystem mounts, sensitive host path
  access, kernel module loading, and privileged capability abuse, including how to drive down
  false positives. Use when authoring or tuning a specific Falco rule for breakout behaviour,
  or triaging a noisy escape-related Falco alert. Keywords: Falco rule, macro, list,
  condition, priority, falco_rules.local.yaml, tuning, false positive. Do not use for
  deploying and operating Falco itself - use detecting-container-runtime-threats-with-falco;
  for tool-agnostic escape signals use detecting-container-escape-attempts.
domain: cybersecurity
subdomain: container-security
tags:
- falco
- container-escape
- runtime-security
- syscall-monitoring
- kubernetes
- detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Token Binding
- Execution Isolation
- File Metadata Consistency Validation
- Restore Access
- Application Protocol Command Analysis
nist_csf:
- PR.PS-01
- PR.IR-01
- ID.AM-08
- DE.CM-01
mitre_attack:
- T1610
- T1611
- T1609
- T1525
- T1068

Detecting Container Escape with Falco Rules

Overview

Falco is a CNCF-graduated runtime security tool that monitors Linux syscalls to detect anomalous container behavior. It uses a rules engine to identify container escape techniques such as mounting host filesystems, accessing sensitive host paths, loading kernel modules, and exploiting privileged container capabilities.

When to Use

  • When investigating security incidents that require detecting container escape with falco rules
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Linux host with kernel 5.8+ (for eBPF driver) or kernel module support
  • Kubernetes cluster (v1.24+) or standalone Docker/containerd
  • Helm 3 for Kubernetes deployment
  • Root or privileged access for driver installation

Installing Falco

Kubernetes Deployment with Helm

# Add Falco Helm chart
helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update

# Install Falco with eBPF driver
helm install falco falcosecurity/falco \
  --namespace falco --create-namespace \
  --set falcosidekick.enabled=true \
  --set falcosidekick.webui.enabled=true \
  --set driver.kind=ebpf \
  --set collectors.containerd.enabled=true \
  --set collectors.containerd.socket=/run/containerd/containerd.sock

# Verify
kubectl get pods -n falco
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=20

Standalone Installation (Debian/Ubuntu)

# Add Falco GPG key and repo
curl -fsSL https://falco.org/repo/falcosecurity-packages.asc | \
  sudo gpg --dearmor -o /usr/share/keyrings/falco-archive-keyring.gpg

echo "deb [signed-by=/usr/share/keyrings/falco-archive-keyring.gpg] https://download.falco.org/packages/deb stable main" | \
  sudo tee /etc/apt/sources.list.d/falcosecurity.list

sudo apt-get update
sudo apt-get install -y falco

# Start Falco
sudo systemctl enable falco
sudo systemctl start falco

Container Escape Detection Rules

Rule 1: Detect Host Mount from Container

- rule: Container Mounting Host Filesystem
  desc: Detect a container attempting to mount the host filesystem
  condition: >
    spawned_process and container and
    proc.name = mount and
    (proc.args contains "/host" or proc.args contains "nsenter")
  output: >
    Container mounting host filesystem
    (user=%user.name container_id=%container.id container_name=%container.name
     image=%container.image.repository command=%proc.cmdline %evt.args)
  priority: CRITICAL
  tags: [container, escape, T1611]

Rule 2: Detect nsenter Usage (Namespace Escape)

- rule: Nsenter Execution in Container
  desc: Detect nsenter being used to escape container namespaces
  condition: >
    spawned_process and container and proc.name = nsenter
  output: >
    nsenter executed in container - potential escape attempt
    (user=%user.name container_id=%container.id image=%container.image.repository
     command=%proc.cmdline parent=%proc.pname)
  priority: CRITICAL
  tags: [container, escape, namespace, T1611]

Rule 3: Detect Privileged Container Launch

- rule: Launch Privileged Container
  desc: Detect a privileged container being launched
  condition: >
    container_started and container and container.privileged=true
  output: >
    Privileged container started
    (user=%user.name container_id=%container.id container_name=%container.name
     image=%container.image.repository)
  priority: WARNING
  tags: [container, privileged, T1610]

Rule 4: Detect /proc/sysrq-trigger Write

- rule: Write to Sysrq Trigger
  desc: Detect writes to /proc/sysrq-trigger which can crash or control the host
  condition: >
    open_write and container and fd.name = /proc/sysrq-trigger
  output: >
    Write to /proc/sysrq-trigger from container
    (user=%user.name container_id=%container.id image=%container.image.repository
     command=%proc.cmdline)
  priority: CRITICAL
  tags: [container, escape, host-manipulation]

Rule 5: Detect Kernel Module Loading from Container

- rule: Container Loading Kernel Module
  desc: Detect a container attempting to load a kernel module
  condition: >
    spawned_process and container and
    (proc.name in (insmod, modprobe) or
     (proc.name = init_module))
  output: >
    Kernel module loading from container
    (user=%user.name container_id=%container.id image=%container.image.repository
     command=%proc.cmdline)
  priority: CRITICAL
  tags: [container, escape, kernel, T1611]

Rule 6: Detect Container Breakout via cgroups

- rule: Write to Cgroup Release Agent
  desc: Detect writes to cgroup release_agent which is a known container escape vector
  condition: >
    open_write and container and
    fd.name endswith release_agent
  output: >
    Container writing to cgroup release_agent - escape attempt
    (user=%user.name container_id=%container.id image=%container.image.repository
     file=%fd.name command=%proc.cmdline)
  priority: CRITICAL
  tags: [container, escape, cgroup, CVE-2022-0492]

Rule 7: Detect Access to Host /etc/shadow

- rule: Container Reading Host Shadow File
  desc: Detect a container reading /etc/shadow on the host via mounted volume
  condition: >
    open_read and container and
    (fd.name = /etc/shadow or fd.name startswith /host/etc/shadow)
  output: >
    Container reading host shadow file
    (user=%user.name container_id=%container.id image=%container.image.repository
     file=%fd.name command=%proc.cmdline)
  priority: CRITICAL
  tags: [container, credential-access, T1003]

Rule 8: Detect Docker Socket Access

- rule: Container Accessing Docker Socket
  desc: Detect a container accessing the Docker socket which allows host control
  condition: >
    (open_read or open_write) and container and
    fd.name = /var/run/docker.sock
  output: >
    Container accessing Docker socket
    (user=%user.name container_id=%container.id image=%container.image.repository
     command=%proc.cmdline)
  priority: CRITICAL
  tags: [container, escape, docker-socket, T1610]

Complete Custom Rules File

# /etc/falco/rules.d/container-escape.yaml
- list: escape_binaries
  items: [nsenter, chroot, unshare, mount, umount, pivot_root]

- macro: container_escape_attempt
  condition: >
    spawned_process and container and
    proc.name in (escape_binaries)

- rule: Container Escape Binary Execution
  desc: Detect execution of binaries commonly used for container escape
  condition: container_escape_attempt
  output: >
    Escape-related binary executed in container
    (user=%user.name container=%container.name image=%container.image.repository
     command=%proc.cmdline parent=%proc.pname pid=%proc.pid)
  priority: CRITICAL
  tags: [container, escape, mitre_T1611]

- rule: Sensitive File Access from Container
  desc: Detect container access to sensitive host files
  condition: >
    (open_read or open_write) and container and
    (fd.name startswith /proc/1/ or
     fd.name = /etc/shadow or
     fd.name = /etc/kubernetes/admin.conf or
     fd.name startswith /var/lib/kubelet/)
  output: >
    Sensitive file accessed from container
    (container=%container.name image=%container.image.repository
     file=%fd.name command=%proc.cmdline user=%user.name)
  priority: CRITICAL
  tags: [container, sensitive-file, mitre_T1005]

Falco Configuration

# /etc/falco/falco.yaml (key settings)
rules_files:
  - /etc/falco/falco_rules.yaml
  - /etc/falco/rules.d/container-escape.yaml

json_output: true
json_include_output_property: true
json_include_tags_property: true

log_stderr: true
log_syslog: true
log_level: info

priority: WARNING

stdout_output:
  enabled: true

syslog_output:
  enabled: true

http_output:
  enabled: true
  url: http://falcosidekick:2801
  insecure: true

grpc:
  enabled: true
  bind_address: "unix:///run/falco/falco.sock"
  threadiness: 8

grpc_output:
  enabled: true

Alert Integration

Forward to Slack via Falcosidekick

# Falcosidekick values.yaml
config:
  slack:
    webhookurl: "https://hooks.slack.com/services/XXXXX"
    minimumpriority: "warning"
    messageformat: |
      *{{.Priority}}* - {{.Rule}}
      Container: {{.OutputFields.container_name}}
      Image: {{.OutputFields.container_image_repository}}
      Command: {{.OutputFields.proc_cmdline}}

Testing Rules

# Simulate container escape attempt (in a test container)
kubectl run test-escape --image=alpine --restart=Never -- sh -c "cat /etc/shadow"

# Simulate nsenter
kubectl run test-nsenter --image=alpine --restart=Never --overrides='{"spec":{"hostPID":true}}' -- nsenter -t 1 -m -u -i -n -- cat /etc/hostname

# Check Falco alerts
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=50 | grep -i escape

Best Practices

  1. Deploy Falco as DaemonSet to ensure coverage on all nodes
  2. Use eBPF driver over kernel module for safer operation
  3. Start with default rules (maturity_stable) then add custom rules
  4. Forward alerts to SIEM/SOAR via Falcosidekick
  5. Tag rules with MITRE ATT&CK technique IDs for correlation
  6. Test rules in permissive mode before enforcing
  7. Tune false positives by adding exception lists for known good processes
  8. Monitor Falco health with Prometheus metrics endpoint

Other files in this skill

assets/template.md (verbatim)

Falco Container Escape Detection Runbook

Alert Triage Template

Alert Details

Field Value
Alert Time
Rule Name
Priority
Container Name
Container Image
Pod Name
Namespace
Node
User
Process Command
MITRE Technique

Triage Steps

Immediate Actions (0-5 minutes)

  • Acknowledge alert in SIEM/SOAR
  • Verify alert is not a false positive (check known exceptions list)
  • Identify the affected pod and node
  • Check if the container is still running

Investigation (5-30 minutes)

  • Capture pod spec: kubectl get pod <name> -n <ns> -o yaml
  • Review container security context
  • Check if container is privileged
  • Review mounted volumes for host paths
  • Examine process tree from Falco output
  • Check for other alerts from same container/node
  • Review Kubernetes audit logs for the same timeframe

Containment (if confirmed)

  • Isolate pod with network policy deny-all
  • Cordon affected node: kubectl cordon <node>
  • Capture forensic data from container
  • Kill compromised container: kubectl delete pod <name> -n <ns>
  • Review other pods on same node for compromise

Recovery

  • Scan node for rootkits
  • Rebuild node if compromise confirmed
  • Patch vulnerable container image
  • Update network policies
  • Uncordon node after verification

False Positive Exceptions

Container Image Rule Justification Approved By Date

Escalation Matrix

Priority Response Time Notify
CRITICAL Immediate Security On-Call + Engineering Lead
WARNING 15 minutes Security On-Call
NOTICE 1 hour Security Team queue
INFO Next business day Review in daily standup

references/api-reference.md (verbatim)

API Reference: Detecting Container Escape with Falco Rules

Falco CLI

falco --version                           # check version
falco --validate /path/to/rules.yaml      # validate rules syntax
falco -r /etc/falco/rules.d/escape.yaml   # load specific rules
falco --list                              # list all available fields
falco --list-events                       # list supported syscalls

Falco Rule Syntax

- rule: <name>
  desc: <description>
  condition: <filter expression>
  output: <alert message with fields>
  priority: <Emergency|Alert|Critical|Error|Warning|Notice|Informational|Debug>
  tags: [tag1, tag2]
  enabled: true

Key Falco Filter Fields

Field Description
container True if event is from a container
spawned_process True if new process spawned
proc.name Process name
proc.cmdline Full command line
proc.pname Parent process name
fd.name File descriptor name/path
container.name Container name
container.image.repository Image repository
container.privileged True if privileged
proc.is_exe_upper_layer Binary not in original image
evt.type Syscall type (setns, unshare, mount)

Falco JSON Output Format

{
  "time": "2024-01-15T10:30:00.000Z",
  "rule": "Container Escape Binary Execution",
  "priority": "Critical",
  "source": "syscall",
  "output": "Escape binary in container...",
  "output_fields": {
    "user.name": "root",
    "proc.cmdline": "nsenter -t 1 -m -u -i -n",
    "container.name": "attacker-pod"
  },
  "tags": ["container", "escape", "T1611"]
}

Falcosidekick Alert Routing

config:
  slack:
    webhookurl: "https://hooks.slack.com/services/XXX"
    minimumpriority: "critical"
  elasticsearch:
    hostport: "https://es:9200"
    index: "falco-alerts"

Helm Deployment

helm repo add falcosecurity https://falcosecurity.github.io/charts
helm install falco falcosecurity/falco \
  --namespace falco --create-namespace \
  --set driver.kind=ebpf \
  --set falcosidekick.enabled=true

CLI Usage

python agent.py --check-status
python agent.py --validate-rules /etc/falco/rules.d/escape.yaml
python agent.py --parse-alerts /var/log/falco/events.json --min-priority Warning
python agent.py --generate-rules > escape-rules.yaml

references/standards.md (verbatim)

Standards and References - Container Escape Detection with Falco

Industry Standards

NIST SP 800-190: Application Container Security Guide

  • Section 4.3: Container Runtime - Monitor containers for anomalous behavior at runtime
  • Section 5.4: Container Runtime Security - Implement runtime monitoring and alerting
  • Recommends syscall-level monitoring for escape detection

CIS Kubernetes Benchmark v1.8

  • 5.7.1: Create administrative boundaries between resources using namespaces
  • 5.7.2: Ensure that the seccomp profile is set to docker/default
  • 5.7.3: Apply Security Context to pods and containers
  • 5.7.4: The default namespace should not be used

MITRE ATT&CK for Containers

Technique ID Name Falco Detection
T1611 Escape to Host nsenter, mount, chroot detection
T1610 Deploy Container Privileged container launch detection
T1003 OS Credential Dumping /etc/shadow access from container
T1005 Data from Local System Sensitive file read detection
T1059 Command and Scripting Interpreter Shell spawn in container
T1068 Exploitation for Privilege Escalation Kernel exploit indicators

NSA/CISA Kubernetes Hardening Guide v1.2

  • Section 5: Audit Logging and Threat Detection
    • Enable runtime security monitoring
    • Detect anomalous container behavior in real-time
    • Monitor for privilege escalation attempts

Falco Rule Maturity Levels

Level Description Count
maturity_stable Production-ready, low false positives 25 rules
maturity_incubating Proven useful, may need tuning ~30 rules
maturity_sandbox Experimental, high false positive rate ~38 rules
maturity_deprecated Scheduled for removal Variable

Known Container Escape CVEs

CVE Description Falco Rule
CVE-2024-21626 runc process.cwd container breakout Detect use of /proc/self/fd to access host
CVE-2022-0492 cgroup v1 release_agent escape Write to Cgroup Release Agent
CVE-2022-0185 File system context exploit Detect unshare in container
CVE-2020-15257 containerd-shim API access Detect abstract socket connections
CVE-2019-5736 runc overwrite host binary Detect writes to /proc/self/exe

Compliance Mappings

PCI DSS v4.0

  • Requirement 10.6.1: Review logs for anomalies at least daily
  • Requirement 11.5: Deploy change-detection mechanisms

SOC 2 Type II

  • CC7.2: Monitor system components for anomalies
  • CC7.3: Evaluate security events to determine impact

references/workflows.md (verbatim)

Workflow - Detecting Container Escape with Falco Rules

Phase 1: Deploy Falco

Install on Kubernetes

helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update

helm install falco falcosecurity/falco \
  --namespace falco --create-namespace \
  --set driver.kind=ebpf \
  --set falcosidekick.enabled=true \
  --set falcosidekick.webui.enabled=true \
  --set collectors.containerd.enabled=true

kubectl -n falco rollout status daemonset/falco --timeout=120s

Verify Deployment

kubectl get pods -n falco -o wide
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=10

Phase 2: Deploy Custom Escape Detection Rules

Create ConfigMap with Custom Rules

kubectl create configmap falco-escape-rules -n falco \
  --from-file=container-escape.yaml=/path/to/container-escape.yaml

# Restart Falco to load new rules
kubectl rollout restart daemonset/falco -n falco

Validate Rules Loaded

kubectl exec -n falco $(kubectl get pod -n falco -l app.kubernetes.io/name=falco -o jsonpath='{.items[0].metadata.name}') -- \
  falco --list | grep -i escape

Phase 3: Test Detection

Test 1 - Privileged Container

kubectl run escape-test-priv --image=alpine --restart=Never \
  --overrides='{"spec":{"containers":[{"name":"test","image":"alpine","command":["sleep","30"],"securityContext":{"privileged":true}}]}}'

# Check alert
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=5 | grep -i privileged
kubectl delete pod escape-test-priv

Test 2 - Sensitive File Access

kubectl run escape-test-shadow --image=alpine --restart=Never -- cat /etc/shadow
kubectl logs -n falco -l app.kubernetes.io/name=falco --tail=5 | grep -i shadow
kubectl delete pod escape-test-shadow

Test 3 - Shell Spawn

kubectl exec -it deploy/some-app -- /bin/sh
# In Falco logs, should see "Terminal shell in container"

Phase 4: Integrate Alerting

Configure Falcosidekick Outputs

# values-sidekick.yaml
config:
  slack:
    webhookurl: "https://hooks.slack.com/services/XXX/YYY/ZZZ"
    minimumpriority: "warning"
  elasticsearch:
    hostport: "https://elasticsearch:9200"
    index: "falco"
    minimumpriority: "notice"
  prometheus:
    enabled: true
helm upgrade falco falcosecurity/falco -n falco \
  -f values-sidekick.yaml

Phase 5: Tune and Maintain

Handle False Positives

# Add exceptions to rules
- rule: Terminal shell in container
  append: true
  exceptions:
    - name: known_shell_spawners
      fields: [container.image.repository]
      comps: [in]
      values:
        - [my-debug-image, kubectl-debug]

Regular Maintenance

  1. Update Falco rules weekly: falcoctl artifact install falco-rules
  2. Review new maturity_stable rules after each Falco release
  3. Correlate Falco alerts with Kubernetes audit logs
  4. Run escape simulation exercises monthly

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.