Eline
banner
eliine.dev
Eline
@eliine.dev
Platform engineer at Telenor. Friend of stuffed animals. Nagging people about #a11y since 2014. she/her
An example rule can be one that detects a shell being executed in a container, like this video.

Here I am executing into a container and getting the /etc/shadow file, which then generates an event in the Falco log.
November 3, 2024 at 7:55 PM