Falco low stable other
Launch Sensitive Mount Container
Detect the initial process launched within a container that has a mount from a sensitive host directory (e.g. /proc). Exceptions are made for known trusted images. This rule holds value for generic auditing; however, its noisiness varies based on your environment.
Detection Logic
container_started and sensitive_mount and not falco_sensitive_mount_containers and not user_sensitive_mount_containers Field Validations
Loading…
Comments (0)
Loading comments...