detecting-container-escape-with-falco-rules
mukul975/Anthropic-Cybersecurity-Skills
This guide details how to write and tune Falco rules to monitor Linux syscalls in real-time. It is designed to detect critical container escape techniques, such as mounting host filesystems, accessing sensitive host paths, loading kernel modules, and exploiting privileged container capabilities. Ideal for security hardening, threat hunting, and incident response in Kubernetes or containerized environments.