Falco low stable other

Launch Sensitive Mount Container

Detect the initial process launched within a container that has a mount from a sensitive host directory (e.g. /proc). Exceptions are made for known trusted images. This rule holds value for generic auditing; however, its noisiness varies based on your environment.

View Source

Detection Logic

container_started and sensitive_mount and not falco_sensitive_mount_containers and not user_sensitive_mount_containers

Field Validations

Loading…

Comments (0)

Loading comments...