sk Skill · mukul975
detecting-container-escape-with-falco-rules
Writes and tunes Falco rule syntax for container escape detection — conditions, macros, lists, priorities, and output fields — covering host filesystem mounts, sensitive host path access, kernel module loading, and privileged capability abuse, including how to drive down false positives. Use when authoring or tuning a specific Falco rule for breakout behaviour, or triaging a noisy escape-related Falco alert.…
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
yamlPythondetectionsyscall-monitoringbashkubernetesruntime-securitycontainer-escapefalco
- Host repository
- mukul975/Anthropic-Cybersecurity-Skills
- Version
- 1.0
- Licence
- Apache-2.0
- Host stars
- 33k
- Host language
- Python