Falco low stable other

Launch Excessively Capable Container

Identify containers that start with a powerful set of capabilities, with exceptions for recognized trusted images. Similar to the "Launch Privileged Container" rule, this functions as a robust auditing rule. Compromised highly privileged containers can lead to substantial harm. For instance, if another rule is triggered within such a container, it might raise suspicion, prompting closer scrutiny.

View Source

Detection Logic

container_started and excessively_capable_container and not falco_privileged_containers and not user_privileged_containers

Field Validations

Loading…

Comments (0)

Loading comments...