mirror of
https://github.com/falcosecurity/falco.git
synced 2026-03-18 18:58:41 +00:00
Example falco alert:
Package management process launched in container (user=root
user_loginuid=-1 command=rpm
--dbpath=/analysis_scratch/de10314b-70bb-4149-802e-1c2c3d47f23c/rpmtmp/rpmdbfinal/var/lib/rpm
-qa --queryformat
[%{FILENAMES}|ANCHORETOK|%{FILEDIGESTS}|ANCHORETOK|%{FILEMODES:octal}|ANCHORETOK|%{FILEGROUPNAME}|ANCHORETOK|%{FILEUSERNAME}|ANCHORETOK|%{FILESIZES}|ANCHORETOK|%{=NAME}|ANCHORETOK|%{FILEFLAGS:fflags}|ANCHORETOK|%{=FILEDIGESTALGO}\n]
container_id=3748cd603f28 container_name=sysdig-image-analyzer image=quay.io/sysdig/node-image-analyzer:latest)
Signed-off-by: Mark Stemm <mark.stemm@gmail.com>