detecting-container-escape-attempts - Detecting Container Escape Attempts with Falco and Seccomp
Monitors container escape indicators using Falco, seccomp profiles, and auditd rules across namespace, capability, kernel, and mount-based attack vectors.
Tags
Updated: 2026-06-30Capabilities
Typical Inputs
Typical Outputs
What this skill does
- deploy Falco runtime detection
- create custom escape detection rules
- configure seccomp profiles
- set up auditd audit rules
- configure alert routing pipeline
- test detection rules with event generator
Inputs
- Linux host with kernel 5.10+
- Falco 0.37+ installation
- Docker Engine or containerd runtime
- auditd service
- Kubernetes cluster
- Alerting service endpoints
Outputs
- Falco alert events
- Seccomp profile files
- Auditd log entries
- Slack and PagerDuty alert notifications
- Elasticsearch alert records
Requirements
- Linux kernel 5.10+ with eBPF support
- Falco 0.37+ with eBPF or kernel module
- Docker Engine or containerd runtime
- auditd installed and configured
- Root access for eBPF/kernel module loading
