Description

Falco

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
falco-talondefault201Critical
falcodefault12Low
falco-k8s-metacollectordefault91Low
falco-falcosidekickdefault01

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 falco-talon

Namespace: default  |  Automount:

🔑 Permissions (20)

RoleResourceVerbsRiskTags
ClusterRole falco-taloncore/nodescreate · get · patch · update · watchCriticalDenialOfService NodeAccess PotentialPrivilegeEscalation Tampering
ClusterRole falco-taloncore/podsdelete · get · list · patch · updateCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadExecution
ClusterRole falco-taloncore/pods/execcreate · getCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole falco-taloncore/namespacesdelete · getHighDenialOfService NamespaceLifecycle ResourceDeletion
ClusterRole falco-taloncore/pods/loggetHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
ClusterRole falco-talonprojectcalico.org/caliconetworkpoliciescreate · get · patch · updateLow
ClusterRole falco-taloncilium.io/ciliumnetworkpoliciescreate · get · patch · updateLow
ClusterRole falco-talonrbac.authorization.k8s.io/clusterrolesdelete · getLow
ClusterRole falco-taloncore/configmapsdelete · getLow
ClusterRole falco-talonapps/daemonsetsdelete · getLow
ClusterRole falco-talonapps/deploymentsdelete · getLow
ClusterRole falco-taloncore/eventscreate · get · patch · updateLow
ClusterRole falco-taloncoordination.k8s.io/leasescreate · get · patch · update · watchLow
ClusterRole falco-talonnetworking.k8s.io/networkpoliciescreate · get · patch · updateLow
ClusterRole falco-taloncore/pods/ephemeralcontainerscreate · patchLow
ClusterRole falco-taloncore/pods/evictioncreate · getLow
ClusterRole falco-talonapps/replicasetsdelete · getLow
ClusterRole falco-talonrbac.authorization.k8s.io/rolesdelete · getLow
ClusterRole falco-taloncore/secretsdelete · getLow
ClusterRole falco-talonapps/statefulsetsdelete · getLow

⚠️ Potential Abuse (9)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentfalco-talonfalco-talonfalco.docker.scarf.sh/falcosecurity/falco-talon:0.3.0

🤖 falco-k8s-metacollector

Namespace: default  |  Automount:

🔑 Permissions (9)

RoleResourceVerbsRiskTags
ClusterRole falco-k8s-metacollectorapps/daemonsetsget · list · watchLow
ClusterRole falco-k8s-metacollectorapps/deploymentsget · list · watchLow
ClusterRole falco-k8s-metacollectorcore/endpointsget · list · watchLow
ClusterRole falco-k8s-metacollectordiscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole falco-k8s-metacollectorcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole falco-k8s-metacollectorcore/podsget · list · watchLow
ClusterRole falco-k8s-metacollectorapps/replicasetsget · list · watchLow
ClusterRole falco-k8s-metacollectorcore/replicationcontrollersget · list · watchLow
ClusterRole falco-k8s-metacollectorcore/servicesget · list · watchLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentfalco-k8s-metacollectork8s-metacollectordocker.io/falcosecurity/k8s-metacollector:0.1.1

🤖 falco

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role falcocore/configmapsget · list · updateLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
DaemonSetfalcofalcodocker.io/falcosecurity/falco:0.41.1
DaemonSetfalcofalcoctl-artifact-followdocker.io/falcosecurity/falcoctl:0.11.2

🤖 falco-falcosidekick

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentfalco-falcosidekickfalcosidekickdocker.io/falcosecurity/falcosidekick:2.31.1