Falco eBPF 容器威胁检测

原名:detecting-container-runtime-threats-with-falco

编写并部署使用现代 eBPF 驱动的 Falco 规则,在 Kubernetes 和 Docker 运行时检测容器逃逸、命名空间滥用、特权挂载及异常系统调用。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-09-07
TRACE 评分
3 / 5

内容概览

Falco is the CNCF graduated runtime-security project (originally by Sysdig) that consumes Linux kernel syscalls and Kubernetes audit events through a driver, evaluates them against a YAML rule engine, and emits real-time alerts. It is the de facto open-source detection tool for runtime threats inside containers, including container escape (MITRE ATT&CK T1611, Escape to Host), namespace manipulation (setns), privileged mounts, reverse shells, and unexpected outbound connections. Falco supports three drivers: the modern eBPF probe (preferred default, requires kernel = 5.8, shipped directly inside the Falco binary so no init container is needed), the legacy eBPF probe, and the kernel module (kmod). Driver selection is handled by falcoctl driver config --type {kmod ebpf modern ebpf} or driver.kind=modern ebpf in the Helm chart. On Kubernetes, Falco runs as a DaemonSet so every node is monito…

查看 SKILL 详情