Default Macros
Use the default macros to simplify Falco Rules
The default Falco rule set defines a number of macros that makes it easier to start writing rules. These macros provide shortcuts for a number of common scenarios and can be used in any user defined rule sets.
Falco also provide Macros that should be overridden. Refer here for further information.
File Opened for Writing
File Opened for Reading
Never True
Always True
Proc Name is Set
File System Object Renamed
New Directory Created
File System Object Removed
File System Object Modified
New Process Spawned
Common Directories for Binaries
Shell is Started
Known Sensitive Files
Newly Created Process
Inbound Network Connections
Outbound Network Connections
Inbound or Outbound Network Connections
Object is a Container
Interactive Process Spawned
Was this page helpful?
Let us know! You feedback will help us to improve the content and to stay in touch with our users.
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.