detecting-container-escape-with-falco-rules
mukul975/Anthropic-Cybersecurity-Skills
Authoring and tuning Falco rules to detect container escape techniques, including host filesystem mounts, nsenter usage, privileged containers, kernel module loading, and host manipulation. Covers rule syntax, condition tuning, output fields, priorities, and false positive reduction.