Presentations for CanSecWest 2022
Bypassing Falco: Cluster Compromise without Tripping the SOC
In this talk I will present my research on various techniques to silently bypass the default Falco ruleset (based on pre-latest v0.30.0). I will demonstrate nine different classes of bypasses, seven of which are novel and have never been presented.