为何简单Falco规则输出中cat命令的文件路径显示为<NA>?
问题原因与解决方案
你的规则里用了spawned_process事件,这个事件是在进程刚创建时触发的。此时cat命令还没开始打开目标文件,fd.name字段没有关联的文件路径,所以会显示<NA>。
要获取被cat打开的文件路径,需要监听文件打开类的事件,具体修改如下:
修改后的Falco规则
- rule: My test rule desc: Alert when cat opens a file condition: file_open and proc.name = cat output: TEST_RULE_ALERT (command=%proc.cmdline pid=%proc.pid file=%fd.name user=%user.name user_loginuid=%user.loginuid container_id=%container.id image=%container.image.repository) priority: notice
说明
- 将触发事件从
spawned_process改为file_open,这个事件会在进程打开文件时触发,此时fd.name会正确填充被打开的文件路径。 - 如果需要更精准监控
cat读取文件的动作,也可以用file_read事件,不过file_open已经能满足获取文件路径的需求。
修改后执行cat /tmp/xyz,输出里的file字段就会显示/tmp/xyz了。
内容的提问来源于stack exchange,提问作者mark
相关产品推荐
相关产品推荐

