diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index 17735cff..be45867a 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -345,8 +345,7 @@ container.image startswith sysdig/falco or container.image startswith sysdig/sysdig or container.image startswith gcr.io/google_containers/hyperkube or - container.image startswith gcr.io/google_containers/kube-proxy or - container.image startswith cchh/sysdig) + container.image startswith gcr.io/google_containers/kube-proxy) - rule: File Open by Privileged Container desc: Any open by a privileged container. Exceptions are made for known trusted images.