mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 08:30:20 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
78 lines
2.3 KiB
Markdown
78 lines
2.3 KiB
Markdown
---
|
|
name: performing-cloud-native-forensics-with-falco
|
|
description: 'Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell
|
|
spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses
|
|
Falco alert output. Use when building container runtime security or investigating k8s cluster compromises.
|
|
|
|
'
|
|
domain: cybersecurity
|
|
subdomain: cloud-security
|
|
tags:
|
|
- performing
|
|
- cloud
|
|
- native
|
|
- forensics
|
|
version: '1.0'
|
|
author: mahipal
|
|
license: Apache-2.0
|
|
nist_csf:
|
|
- PR.IR-01
|
|
- ID.AM-08
|
|
- GV.SC-06
|
|
- DE.CM-01
|
|
---
|
|
|
|
# Performing Cloud Native Forensics with Falco
|
|
|
|
|
|
## When to Use
|
|
|
|
- When conducting security assessments that involve performing cloud native forensics with falco
|
|
- When following incident response procedures for related security events
|
|
- When performing scheduled security testing or auditing activities
|
|
- When validating security controls through hands-on testing
|
|
|
|
## Prerequisites
|
|
|
|
- Familiarity with cloud security concepts and tools
|
|
- Access to a test or lab environment for safe execution
|
|
- Python 3.8+ with required dependencies installed
|
|
- Appropriate authorization for any testing activities
|
|
|
|
## Instructions
|
|
|
|
Deploy and manage Falco rules for runtime security detection in containerized
|
|
environments. Parse Falco alerts for incident response.
|
|
|
|
```yaml
|
|
# Custom Falco rule for detecting shell in container
|
|
- rule: Shell Spawned in Container
|
|
desc: Detect shell process started in a container
|
|
condition: >
|
|
spawned_process and container
|
|
and proc.name in (bash, sh, zsh, dash, csh)
|
|
and not proc.pname in (docker-entrypo, supervisord)
|
|
output: >
|
|
Shell spawned in container
|
|
(user=%user.name command=%proc.cmdline container=%container.name
|
|
image=%container.image.repository)
|
|
priority: WARNING
|
|
tags: [container, shell, mitre_execution]
|
|
```
|
|
|
|
Key detection rules:
|
|
1. Shell spawn in non-interactive containers
|
|
2. Sensitive file access (/etc/shadow, /etc/passwd)
|
|
3. Outbound connections from unexpected containers
|
|
4. Privilege escalation via setuid/setgid
|
|
5. Container escape via mount or ptrace
|
|
|
|
## Examples
|
|
|
|
```bash
|
|
# Run Falco with custom rules
|
|
falco -r /etc/falco/custom_rules.yaml -o json_output=true
|
|
# Parse JSON alerts
|
|
cat /var/log/falco/alerts.json | python3 -c "import json,sys; [print(json.loads(l)['output']) for l in sys.stdin]"
|
|
```
|