Falco informational stable other

Unexpected K8s NodePort Connection

Detect attempts to utilize K8s NodePorts from a container. K8s NodePorts are accessible on the eth0 interface of each node, and they facilitate external traffic into a Kubernetes cluster. Attackers could misuse them for unauthorized access. The rule uses default port ranges, but check for custom ranges and make necessary adjustments. Also, consider tuning this rule as needed.

View Source

Detection Logic

inbound_outbound and container and fd.sport >= 30000 and fd.sport <= 32767 and not nodeport_containers

Field Validations

Loading…

Comments (0)

Loading comments...