Telemetry coverage
Rules detecting the same action
These rules filter on the same operation.
- Kubernetes Multi-Resource Discovery (Elastic)
- Kubernetes Pod Exec Cloud Instance Metadata Access (Elastic)
- Kubernetes Pod Exec Potential Reverse Shell (Elastic)
- Kubernetes Pod Exec Sensitive File or Credential Path Access (Elastic)
- Kubernetes Pod Exec with Curl or Wget to HTTPS (Elastic)
- Kubernetes Unusual Decision by User Agent (Elastic)
- Unauthorized Kubernetes Pod Execution (Panther)
- Unauthorized Kubernetes Pod Execution (Panther)
Stages and Predicates
Stage 1: falco_condition
and
not
jevt.rawtime eq "0"
objectRef.subresource eq "portforward"
Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
jevt.rawtime | eq | 0 | excludes:jevt.rawtime field:"jevt.rawtime" value:"0" |
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
objectRef.subresource | in |
| field:"objectRef.subresource" kind:in value:"portforward" |