Skip to content

Testing Rules

Falco rules are YAML files that define conditions for detecting security anomalies in containerized environments. By crafting rules that match specific events (e.g., process executions, file accesses, or network activity), you can create targeted detection logic for Kubernetes workloads. This section guides you through writing and testing basic rules using Falco's rule syntax and testing framework.


Rule Structure and Syntax

A basic Falco rule consists of the following fields: - rule: A short name for the rule (e.g., Privileged Container Execution). - description: A brief explanation of the rule's purpose. - condition: A logical expression using event fields (e.g., container.image or process.name) to define when the rule triggers. - output: A message displayed when the rule matches (optional but recommended for clarity).

Example rule for detecting privileged container executions:

rule: Privileged Container Execution
description: Detects containers running with privileged mode
condition: container.image != "trusted-image" and container.privileged: true
output: "Detected privileged container execution: %container.image%"


Writing Your First Rule

  1. Identify the event you want to detect. For example:
  2. A process executing with elevated privileges.
  3. A container accessing a sensitive file.
  4. A network connection to a suspicious IP.

  5. Use Falco's event fields to construct the condition. Common fields include:

  6. container.id: Unique identifier for a container.
  7. process.name: Name of the process.
  8. file.path: Path to a file accessed.
  9. network.direction: Direction of network traffic (inbound/outbound).

  10. Combine conditions using logical operators (and, or, not). For example:

    condition: file.path contains "/etc/passwd" and file.perm != "0644"
    


Managing Rule Priority and Weight

When multiple rules match the same event, use the priority field to define rule precedence. Higher numerical values indicate higher priority. This ensures critical rules take precedence and avoids conflicts.

Example rule with priority:

rule: Critical Privileged Container Execution
description: Detects high-risk privileged container executions
condition: container.image != "trusted-image" and container.privileged: true
priority: 100
output: "CRITICAL: Detected privileged container execution: %container.image%"


Testing Rules with falco --test

Falco provides a testing framework to validate rules without deploying them to a live environment. Use the --test flag with a test file containing simulated events:

  1. Create a test file (e.g., test.yaml) with a simulated event:

    - event: process
      values:
        container.id: "abc123"
        container.image: "malicious-image"
        container.privileged: true
    

  2. Run Falco with the test file:

    falco --test test.yaml --rule-dir ./rules
    
    Replace ./rules with the directory containing your rule files.

  3. Verify output: If the rule matches, Falco will display the output message. For example:

    Detected privileged container execution: malicious-image
    


Debugging and Refining Rules

  • Use --format json to inspect raw event data:

    falco --format json --test test.yaml
    
    This helps validate that event fields match your rule's conditions.

  • Check Falco logs (/var/log/falco/falco.log) for detailed debugging when rules fail to trigger.

  • Avoid over-reliance on single events. Combine multiple conditions (e.g., container.image + process.name) to reduce false positives.


Key takeaways

  • Falco rules use YAML to define conditions based on event fields like container.image or process.name.
  • Test rules locally with falco --test to validate logic before deployment.
  • Use --format json to debug event data and refine rule conditions.
  • Prioritize context-aware rules (e.g., combining multiple fields) to improve accuracy.
  • Use the priority field to manage rule precedence and avoid conflicts.