LogoClawIndex
CasesSkillsAbout
LogoClawIndex

detecting-container-escape-attempts - Detecting Container Escape Attempts with Falco and Seccomp

Monitors container escape indicators using Falco, seccomp profiles, and auditd rules across namespace, capability, kernel, and mount-based attack vectors.

Tags

Updated: 2026-06-30
containerskubernetesdockersecurityruntime-securityescape-detectionfalcoseccompauditdebpf

Capabilities

deploy Falco runtime detectioncreate custom escape detection rulesconfigure seccomp profilesset up auditd audit rules

Typical Inputs

Linux host with kernel 5.10+Falco 0.37+ installationDocker Engine or containerd runtime

Typical Outputs

Falco alert eventsSeccomp profile filesAuditd log entries

What this skill does

  • deploy Falco runtime detection
  • create custom escape detection rules
  • configure seccomp profiles
  • set up auditd audit rules
  • configure alert routing pipeline
  • test detection rules with event generator

Inputs

  • Linux host with kernel 5.10+
  • Falco 0.37+ installation
  • Docker Engine or containerd runtime
  • auditd service
  • Kubernetes cluster
  • Alerting service endpoints

Outputs

  • Falco alert events
  • Seccomp profile files
  • Auditd log entries
  • Slack and PagerDuty alert notifications
  • Elasticsearch alert records

Requirements

  • Linux kernel 5.10+ with eBPF support
  • Falco 0.37+ with eBPF or kernel module
  • Docker Engine or containerd runtime
  • auditd installed and configured
  • Root access for eBPF/kernel module loading

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.