cloud-platform-skills / skills
mchittineni/cloud-platform-skills/.cursor/rules/skills/container-runtime-security-falco.mdc
Runtime threat detection with Falco and eBPF: custom rule authoring, syscall and Kubernetes audit sources, macros, lists and exceptions for tuning, alert routing, and response playbooks. Use when alerting on attacker behaviour inside a running container such as an interactive shell being opened in production, writing or tuning a noisy Falco rule, or triaging a runtime alert.
What's in it
- Runtime Security & Threat Detection with Falco and eBPF
- When to Use This Skill
- 1. Custom Falco Security Rules (falcorules.local.yaml)
- 2. Runtime Security Operational Playbook
- 3. Tuning: Macros, Lists & Exceptions
---
description: "Runtime threat detection with Falco and eBPF: custom rule authoring, syscall and Kubernetes audit sources, macros, lists and exceptions for tuning, alert routing, and response playbooks. Use when alerting on attacker behaviour inside a running container such as an interactive shell being opened in production, writing or tuning a noisy Falco rule, or triaging a runtime alert."
globs:
alwaysApply: false
---
# Runtime Security & Threat Detection with Falco and eBPF
## When to Use This Skill
**Triggers — load this skill when:**
- Runtime detection coverage is needed for containers or Kubernetes nodes
- A Falco rule must be written, scoped, or tuned against noise
- A runtime alert (shell in container, sensitive mount, crypto-miner) needs triage
**Route elsewhere when:**
- Pre-deploy image hardening -> `docker-containerization-basics`
- Full incident containment and forensics -> `secops-incident-triage-forensics`
- Cloud control-plane misconfiguration -> `cloud-security-posture-cspm-cis`
## 1. Custom Falco Security Rules (`falco_rules.local.yaml`)
```yaml
- rule: Terminal Shell Spawned Inside Production Container
desc: Detect interactive shell execution (bash/sh) within production pods
condition: >
spawned_process and container
and (k8s.ns.name = "production")
and (proc.name in (bash, sh, zsh, ksh, csh))
and not user_expected_debug_shell
output: >
CRITICAL: Shell spawned in container (user=%user.name pod=%k8s.pod.name
ns=%k8s.ns.name image=%container.image.repository cmdline=%proc.cmdline)
priority: CRITICAL
tags: [container, mitre_execution, pci_dss]
- rule: Sensitive File Access Under /etc
desc: Detect unexpected modification of system configuration files
condition: >
open_write and container
and fd.name startswith "/etc"
and not proc.name in (dpkg, apt, apk)
output: >
WARNING: File modified in /etc (file=%fd.name proc=%proc.name container=%container.name)
priority: WARNING
tags: [filesystem, mitre_persistence]
```
---
## 2. Runtime Security Operational Playbook
1. **Alert Routing**: Forward Falco alerts via Falcosidekick directly to Slack, PagerDuty, and SIEM (Elasticsearch/Splunk).
2. **Automated Containment**: Integrate Falco with Kubernetes webhook responders to isolate or terminate compromised pods automatically.
3. **Read-Only Root Filesystems**: Combine runtime monitoring with `readOnlyRootFilesystem: true` in Pod Security Standards.
---
## 3. Tuning: Macros, Lists & Exceptions
Noise is a security failure, not an inconvenience: a muted channel detects nothing. Tune by
narrowing the rule, never by disabling it.
```yaml
- list: trusted_debug_images
items: ["company/debug-toolbox", "company/netshoot"]
- macro: from_trusted_debug
condition: container.image.repository in (trusted_debug_images)
- rule: Terminal shell in container
desc: A shell was spawned in a container outside the sanctioned debug path
condition: >
spawned_process and container and shell_procs
and not from_trusted_debug
and not k8s.ns.name in (kube-system, falco)
output: "Shell in container (user=%user.name ns=%k8s.ns.name pod=%k8s.pod.name cmd=%proc.cmdline)"
priority: WARNING
tags: [container, shell, mitre_execution]
exceptions:
- name: ci_test_runner
fields: [k8s.ns.name, proc.name]
comps: [=, =]
values: [[ci-runners, sh]]
```
Discipline that keeps the signal alive:
- Prefer `exceptions:` (structured, reviewable, per-field) over appending `and not ...` chains.
- Set `priority` so paging maps to CRITICAL/ERROR only; WARNING goes to a queue, not a pager.
- Review the top five noisiest rules weekly; a rule firing hundreds of times a day is either
mis-scoped or describes normal behaviour that should be fixed at the source.
More agent context in mchittineni/cloud-platform-skills
167 other files this repository gives its agents, the first 60 shown.
AGENTS.md
CLAUDE.md
Copilot instructions
Cursor rule
- .cursor/rules/00-index.mdc
- .cursor/rules/skills/ai-agent-security-llm-threats.mdc
- .cursor/rules/skills/api-gateway-service-mesh.mdc
- .cursor/rules/skills/aws-cloud-migration-strategies.mdc
- .cursor/rules/skills/aws-eks-enterprise-patterns.mdc
- .cursor/rules/skills/aws-iam-zero-trust-policies.mdc
- .cursor/rules/skills/azure-aks-enterprise-landing-zones.mdc
- .cursor/rules/skills/azure-cloud-engineering-patterns.mdc
- .cursor/rules/skills/backup-and-disaster-recovery.mdc
- .cursor/rules/skills/chaos-engineering-resilience-testing.mdc
- .cursor/rules/skills/cicd-pipeline-design.mdc
- .cursor/rules/skills/cloud-native-microservices-patterns.mdc
- .cursor/rules/skills/cloud-security-posture-cspm-cis.mdc
- .cursor/rules/skills/configuration-management-ansible.mdc
- .cursor/rules/skills/database-devops-lifecycle.mdc
- .cursor/rules/skills/detection-engineering-threat-hunting.mdc
- .cursor/rules/skills/devops-metrics-dora-kpis.mdc
- .cursor/rules/skills/docker-containerization-basics.mdc
- .cursor/rules/skills/enterprise-iac-governance-terragrunt.mdc
- .cursor/rules/skills/finops-framework-inform-optimize-operate.mdc
- .cursor/rules/skills/gcp-cloud-engineering-patterns.mdc
- .cursor/rules/skills/gcp-gke-autopilot-multi-tenant.mdc
- .cursor/rules/skills/git-branching-merge-strategies.mdc
- .cursor/rules/skills/gitops-multi-cluster-argo-flux.mdc
- .cursor/rules/skills/helm-kubernetes-deployment.mdc
- .cursor/rules/skills/incident-management-and-postmortem.mdc
- .cursor/rules/skills/infrastructure-host-monitoring.mdc
- .cursor/rules/skills/internal-developer-portal-backstage.mdc
- .cursor/rules/skills/linux-sysadmin-troubleshooting.mdc
- .cursor/rules/skills/performance-load-testing.mdc
- .cursor/rules/skills/policy-as-code-opa-kyverno.mdc
- .cursor/rules/skills/prometheus-grafana-otel-tracing.mdc
- .cursor/rules/skills/scalability-high-availability-patterns.mdc
- .cursor/rules/skills/scripting-and-automation.mdc
- .cursor/rules/skills/secops-incident-triage-forensics.mdc
- .cursor/rules/skills/secrets-management-vault-kms.mdc
- .cursor/rules/skills/serverless-event-driven-architecture.mdc
- .cursor/rules/skills/shift-left-security-sast-sca.mdc
- .cursor/rules/skills/sli-slo-error-budget-design.mdc
- .cursor/rules/skills/supply-chain-security-slsa-sigstore.mdc
- .cursor/rules/skills/terraform-iac-modules.mdc
- .cursor/rules/skills/write-a-skill.mdc
- .cursor/rules/skills/zero-downtime-release-strategies.mdc
Skill
- ai-agent-security-llm-threats.agents/skills/ai-agent-security-llm-threats/SKILL.md
- api-gateway-service-mesh.agents/skills/api-gateway-service-mesh/SKILL.md
- aws-cloud-migration-strategies.agents/skills/aws-cloud-migration-strategies/SKILL.md
- aws-eks-enterprise-patterns.agents/skills/aws-eks-enterprise-patterns/SKILL.md
- aws-iam-zero-trust-policies.agents/skills/aws-iam-zero-trust-policies/SKILL.md
- azure-aks-enterprise-landing-zones.agents/skills/azure-aks-enterprise-landing-zones/SKILL.md
- azure-cloud-engineering-patterns.agents/skills/azure-cloud-engineering-patterns/SKILL.md
- backup-and-disaster-recovery.agents/skills/backup-and-disaster-recovery/SKILL.md
- chaos-engineering-resilience-testing.agents/skills/chaos-engineering-resilience-testing/SKILL.md
- cicd-pipeline-design.agents/skills/cicd-pipeline-design/SKILL.md
- cloud-native-microservices-patterns.agents/skills/cloud-native-microservices-patterns/SKILL.md
- cloud-security-posture-cspm-cis.agents/skills/cloud-security-posture-cspm-cis/SKILL.md
- configuration-management-ansible.agents/skills/configuration-management-ansible/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
Reports can't be read right now.
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

