Falco low stable other
Launch Disallowed Container
Detect the initial process launched within a container that is not in a list of allowed containers. This rule holds value for generic auditing; however, this rule requires a good understanding of your setup and consistent effort to keep the list of allowed containers current. In some situations, this can be challenging to manage.
Detection Logic
container_started and not allowed_containers Field Validations
Loading…
Comments (0)
Loading comments...