Falco eBPF 容器威胁检测
原名:detecting-container-runtime-threats-with-falco
编写并部署使用现代 eBPF 驱动的 Falco 规则,在 Kubernetes 和 Docker 运行时检测容器逃逸、命名空间滥用、特权挂载及异常系统调用。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-07
- TRACE 评分
- 3 / 5
内容概览
Falco is the CNCF graduated runtime-security project (originally by Sysdig) that consumes Linux kernel syscalls and Kubernetes audit events through a driver, evaluates them against a YAML rule engine, and emits real-time alerts. It is the de facto open-source detection tool for runtime threats inside containers, including container escape (MITRE ATT&CK T1611, Escape to Host), namespace manipulation (setns), privileged mounts, reverse shells, and unexpected outbound connections. Falco supports three drivers: the modern eBPF probe (preferred default, requires kernel = 5.8, shipped directly inside the Falco binary so no init container is needed), the legacy eBPF probe, and the kernel module (kmod). Driver selection is handled by falcoctl driver config --type {kmod ebpf modern ebpf} or driver.kind=modern ebpf in the Helm chart. On Kubernetes, Falco runs as a DaemonSet so every node is monito…