BigHugger
sk Skill · mukul975

detecting-container-escape-with-falco-rules

Writes and tunes Falco rule syntax for container escape detection — conditions, macros, lists, priorities, and output fields — covering host filesystem mounts, sensitive host path access, kernel module loading, and privileged capability abuse, including how to drive down false positives. Use when authoring or tuning a specific Falco rule for breakout behaviour, or triaging a noisy escape-related Falco alert.…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
yamlPythondetectionsyscall-monitoringbashkubernetesruntime-securitycontainer-escapefalco
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python