Falco — runtime security

Falco
Active
Events in 24h: 73
Critical
0
Events in 24h
Warnings
7
Notices: 12
Top rules
5
Total: 73
Top rules
Run shell untrusted 2
Terminal shell in container 1
Read sensitive file untrusted 1
Write below etc 1
Detect outbound connections to common miner pools 1
Recent events 73
warning 2026-10-11T19:27:28 warning A Run shell untrusted (user=root command=sh pid=6495)
warning 2026-10-11T19:08:53 warning A Write below etc (user=root command=sh pid=5884)
warning 2026-10-11T18:55:06 warning A Terminal shell in container (user=root command=sh pid=5567)
notice 2026-10-11T17:47:22 notice A Run shell untrusted (user=root command=sh pid=4756)
notice 2026-10-11T18:18:12 notice A Detect outbound connections to common miner pools (user=root command=sh pid=7118)
notice 2026-10-11T16:33:38 notice A Run shell untrusted (user=root command=sh pid=4721)
warning 2026-10-11T18:02:40 warning A Run shell untrusted (user=root command=sh pid=1932)
notice 2026-10-11T13:43:32 notice A Detect outbound connections to common miner pools (user=root command=sh pid=9257)
warning 2026-10-11T15:54:08 warning A Run shell untrusted (user=root command=sh pid=5259)
notice 2026-10-11T15:37:31 notice A Terminal shell in container (user=root command=sh pid=3757)
warning 2026-10-11T15:58:48 warning A Detect outbound connections to common miner pools (user=root command=sh pid=2173)
notice 2026-10-11T13:38:35 notice A Terminal shell in container (user=root command=sh pid=4651)
notice 2026-10-11T13:48:16 notice A Run shell untrusted (user=root command=sh pid=7388)
notice 2026-10-11T13:59:39 notice A Read sensitive file untrusted (user=root command=sh pid=7572)
notice 2026-10-11T14:57:16 notice A Run shell untrusted (user=root command=sh pid=6564)
warning 2026-10-11T11:08:58 warning A Detect outbound connections to common miner pools (user=root command=sh pid=7915)
notice 2026-10-11T13:28:48 notice A Write below etc (user=root command=sh pid=8032)
Tuning: silence a false positive

The panel does not change the Falco config — it only shows the snippet and commands you apply on the server over SSH.

1. Create an override file with the exclusion:
# /etc/falco/rules.d/local-tuning.yaml
- rule: <EXACT RULE NAME from the list above>
  condition: and not fd.name = /path/to/exclude
  append: true
2. Check and restart Falco:
sudo nano /etc/falco/rules.d/local-tuning.yaml
sudo falco --validate /etc/falco/rules.d/local-tuning.yaml
sudo systemctl restart falco 2>/dev/null || sudo systemctl restart falco-modern-bpf

Use the exact rule name. If the list shows the message text instead of a name, enable JSON output in falco.yaml (json_output: true) so the dashboard receives exact rule names.

Running Falco on a plain server, without Kubernetes

Falco is usually discussed as a Kubernetes tool, and most of what is written about it assumes a cluster. It works perfectly well on an ordinary Linux server, where it watches system calls and raises an alert when a process does something it has no business doing — spawning a shell from a web server, writing to a system binary directory, reading sensitive files, opening an unexpected outbound connection.

This page shows the alerts with their priority, the rule that fired, and the process and command line behind them. That last detail is what makes Falco different from log-based tools: it reports what a process actually did, not what a service chose to write about it.

The default rule set is written with containers in mind and will be noisy on a bare server until it is tuned. Package managers, backup jobs and cron scripts routinely trip rules meant to catch intruders. Budget an hour or two of silencing legitimate behaviour before the output becomes something you can act on — an alert stream nobody reads is the same as no alerting at all.