Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

Detecting MITRE ATT&CK: Defense evasion techniques with Falco

Blog post from Sysdig

Post Details
Company
Date Published
Author
Kaizhe Huang
Word Count
1,690
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

MITRE ATT&CK's defense evasion techniques are strategies used by attackers to bypass security measures, and understanding them is crucial for securing infrastructure. The article explains how these techniques are grouped within the MITRE ATT&CK framework and highlights the role of Falco, an open-source runtime threat detection tool, in identifying such threats in container environments. Falco can detect changes to setuid or setgid bits on files and attempts to disable security tools like ufw, AppArmor, and SELinux, thereby enhancing security by monitoring for abnormal behavior in real-time. The article also discusses how attackers might exploit elevation control mechanisms or disable security tools to gain unauthorized access or maintain persistence, illustrating the necessity of runtime security tools like Falco to protect containerized applications.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 5 1,091 139 49 +36%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.