Falco low stable other

Launch Disallowed Container

Detect the initial process launched within a container that is not in a list of allowed containers. This rule holds value for generic auditing; however, this rule requires a good understanding of your setup and consistent effort to keep the list of allowed containers current. In some situations, this can be challenging to manage.

View Source

Detection Logic

container_started and not allowed_containers

Field Validations

Loading…

Comments (0)

Loading comments...