Falco — 运行时安全

Falco
运行中
24 小时内事件数: 37
严重
0
24 小时内事件数
警告数
9
通知数: 11
热门规则
5
合计: 37
热门规则
Terminal shell in container 3
Write below etc 2
Read sensitive file untrusted 1
Detect outbound connections to common miner pools 1
Run shell untrusted 0
最近事件 37
warning 2026-10-11T23:33:48 warning A Write below etc (user=root command=sh pid=8610)
notice 2026-10-11T23:27:31 notice A Run shell untrusted (user=root command=sh pid=9105)
warning 2026-10-11T23:09:32 warning A Write below etc (user=root command=sh pid=8223)
warning 2026-10-11T22:31:54 warning A Detect outbound connections to common miner pools (user=root command=sh pid=2578)
notice 2026-10-11T21:37:40 notice A Terminal shell in container (user=root command=sh pid=9306)
warning 2026-10-11T22:24:43 warning A Read sensitive file untrusted (user=root command=sh pid=5357)
notice 2026-10-11T19:49:42 notice A Run shell untrusted (user=root command=sh pid=1639)
warning 2026-10-11T19:21:06 warning A Run shell untrusted (user=root command=sh pid=5232)
notice 2026-10-11T20:16:28 notice A Terminal shell in container (user=root command=sh pid=4295)
notice 2026-10-11T22:44:36 notice A Write below etc (user=root command=sh pid=1271)
notice 2026-10-11T20:04:38 notice A Terminal shell in container (user=root command=sh pid=2797)
warning 2026-10-11T16:13:15 warning A Detect outbound connections to common miner pools (user=root command=sh pid=9855)
notice 2026-10-11T17:39:00 notice A Detect outbound connections to common miner pools (user=root command=sh pid=5559)
warning 2026-10-11T14:50:46 warning A Write below etc (user=root command=sh pid=2909)
notice 2026-10-11T20:46:30 notice A Write below etc (user=root command=sh pid=4847)
warning 2026-10-11T13:52:33 warning A Run shell untrusted (user=root command=sh pid=4202)
warning 2026-10-11T11:35:08 warning A Read sensitive file untrusted (user=root command=sh pid=9044)
notice 2026-10-11T17:16:07 notice A Detect outbound connections to common miner pools (user=root command=sh pid=4231)
notice 2026-10-11T10:17:00 notice A Detect outbound connections to common miner pools (user=root command=sh pid=6059)
调优:屏蔽误报

面板不会修改 Falco 配置——只显示代码片段和命令,供您通过 SSH 在服务器上执行。

1. 创建包含排除项的覆盖文件:
# /etc/falco/rules.d/local-tuning.yaml
- rule: <上方列表中的精确规则名称>
  condition: and not fd.name = /path/to/exclude
  append: true
2. 检查并重启 Falco:
sudo nano /etc/falco/rules.d/local-tuning.yaml
sudo falco --validate /etc/falco/rules.d/local-tuning.yaml
sudo systemctl restart falco 2>/dev/null || sudo systemctl restart falco-modern-bpf

请使用准确的规则名称。如果列表中显示的是消息文本而非名称,请在 falco.yaml 中启用 JSON 输出(json_output: true),面板即可获取准确的规则名称。

在普通服务器上跑 Falco,不用 Kubernetes

人们谈起 Falco,通常把它当作 Kubernetes 的工具,关于它的文字也几乎都默认存在一个集群。它在一台再普通不过的 Linux 服务器上同样跑得很好:在那里它监视系统调用,并在某个进程做出与它无关的事情时发出告警——从 Web 服务器里拉起一个 shell、往系统二进制目录里写入、读取敏感文件,或者打开一条意料之外的出站连接。

这一页展示告警及其优先级、触发的规则,以及背后的进程和命令行。恰恰是最后这个细节把 Falco 与基于日志的工具区分开来:它报告的是一个进程实际做了什么,而不是某个服务选择就此写下什么。

默认规则集是照着容器写的,在一台裸机服务器上,未经调校之前它会很吵。软件包管理器、备份任务和 cron 脚本会经常触发那些本为抓捕入侵者而设的规则。在输出变得可用之前,请预留一两个小时去让合法行为闭嘴:没人看的告警流,与根本没有告警是一回事。