<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Falco on IT it's FUN</title><link>https://mksit.sknt.ru/tags/falco/</link><description>Recent content in Falco on IT it's FUN</description><generator>Hugo</generator><language>ru</language><lastBuildDate>Tue, 20 Jan 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://mksit.sknt.ru/tags/falco/index.xml" rel="self" type="application/rss+xml"/><item><title>Falco - замена auditd. Интеграция с wazuh</title><link>https://mksit.sknt.ru/posts/falco/</link><pubDate>Tue, 20 Jan 2026 00:00:00 +0000</pubDate><guid>https://mksit.sknt.ru/posts/falco/</guid><description>&lt;p&gt;Это современная альтернатива auditd, перехватывает системные запросы ядра&lt;/p&gt;
&lt;p&gt;&lt;a href="https://wazuh.com/blog/cloud-native-security-with-wazuh-and-falco/" class="external-link" target="_blank" rel="noopener"&gt;https://wazuh.com/blog/cloud-native-security-with-wazuh-and-falco/&lt;/a&gt;
&lt;a href="https://falco.org/docs/getting-started/falco-linux-quickstart/" class="external-link" target="_blank" rel="noopener"&gt;https://falco.org/docs/getting-started/falco-linux-quickstart/&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="установка-falco-на-серверах-с-wazuh-agent"&gt;
 Установка falco на серверах с wazuh-agent
 &lt;a class="heading-link" href="#%d1%83%d1%81%d1%82%d0%b0%d0%bd%d0%be%d0%b2%d0%ba%d0%b0-falco-%d0%bd%d0%b0-%d1%81%d0%b5%d1%80%d0%b2%d0%b5%d1%80%d0%b0%d1%85-%d1%81-wazuh-agent"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Ссылка на заголовок"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Ссылка на заголовок&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sh" data-lang="sh"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# настраиваем репу&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl -fsSL https://falco.org/repo/falcosecurity-packages.asc &lt;span class="p"&gt;|&lt;/span&gt; gpg --dearmor -o /usr/share/keyrings/falco-archive-keyring.gpg
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;deb [signed-by=/usr/share/keyrings/falco-archive-keyring.gpg] https://download.falco.org/packages/deb stable main&amp;#34;&lt;/span&gt; &amp;gt; /etc/apt/sources.list.d/falcosecurity.list
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;apt update
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# зависимость для ответов установщика&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;apt-get install -y dialog
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;apt install -y falco
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;systemctl status falco-modern-bpf
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# проверяем, провоцируем&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;cat /etc/shadow &amp;gt; /dev/null
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;journalctl &lt;span class="nv"&gt;_COMM&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;falco -p warning
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;grep Sensitive /var/log/syslog
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;systemctl restart wazuh-agent falco-modern-bpf
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="настройка-wazuh-server"&gt;
 Настройка wazuh-server
 &lt;a class="heading-link" href="#%d0%bd%d0%b0%d1%81%d1%82%d1%80%d0%be%d0%b9%d0%ba%d0%b0-wazuh-server"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Ссылка на заголовок"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Ссылка на заголовок&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;конфиг для агентов /var/ossec/etc/shared/default/agent.conf&lt;/p&gt;</description></item></channel></rss>