Testing Rules
Falco rules are YAML files that define conditions for detecting security anomalies in containerized environments. By crafting rules that match specific events (e.g., process executions, file accesses, or network activity), you can create targeted detection logic for Kubernetes workloads. This section guides you through writing and testing basic rules using Falco's rule syntax and testing framework.
Rule Structure and Syntax¶
A basic Falco rule consists of the following fields:
- rule: A short name for the rule (e.g., Privileged Container Execution).
- description: A brief explanation of the rule's purpose.
- condition: A logical expression using event fields (e.g., container.image or process.name) to define when the rule triggers.
- output: A message displayed when the rule matches (optional but recommended for clarity).
Example rule for detecting privileged container executions:
rule: Privileged Container Execution
description: Detects containers running with privileged mode
condition: container.image != "trusted-image" and container.privileged: true
output: "Detected privileged container execution: %container.image%"
Writing Your First Rule¶
- Identify the event you want to detect. For example:
- A process executing with elevated privileges.
- A container accessing a sensitive file.
-
A network connection to a suspicious IP.
-
Use Falco's event fields to construct the condition. Common fields include:
container.id: Unique identifier for a container.process.name: Name of the process.file.path: Path to a file accessed.-
network.direction: Direction of network traffic (inbound/outbound). -
Combine conditions using logical operators (
and,or,not). For example:
Managing Rule Priority and Weight¶
When multiple rules match the same event, use the priority field to define rule precedence. Higher numerical values indicate higher priority. This ensures critical rules take precedence and avoids conflicts.
Example rule with priority:
rule: Critical Privileged Container Execution
description: Detects high-risk privileged container executions
condition: container.image != "trusted-image" and container.privileged: true
priority: 100
output: "CRITICAL: Detected privileged container execution: %container.image%"
Testing Rules with falco --test¶
Falco provides a testing framework to validate rules without deploying them to a live environment. Use the --test flag with a test file containing simulated events:
-
Create a test file (e.g.,
test.yaml) with a simulated event: -
Run Falco with the test file:
Replace./ruleswith the directory containing your rule files. -
Verify output: If the rule matches, Falco will display the
outputmessage. For example:
Debugging and Refining Rules¶
-
Use
This helps validate that event fields match your rule's conditions.--format jsonto inspect raw event data: -
Check Falco logs (
/var/log/falco/falco.log) for detailed debugging when rules fail to trigger. -
Avoid over-reliance on single events. Combine multiple conditions (e.g.,
container.image+process.name) to reduce false positives.
Key takeaways¶
- Falco rules use YAML to define conditions based on event fields like
container.imageorprocess.name. - Test rules locally with
falco --testto validate logic before deployment. - Use
--format jsonto debug event data and refine rule conditions. - Prioritize context-aware rules (e.g., combining multiple fields) to improve accuracy.
- Use the
priorityfield to manage rule precedence and avoid conflicts.