Tracee Runtime Security Series: Writing Custom Tracee Rules
ID: ce8b0dc3-5693-5f86-8bfb-e3d1605cd61b
STIX ID: report--ce8b0dc3-5693-5f86-8bfb-e3d1605cd61b
Feed Name: Aqua Security Blog
This blog explains how to author and test a Tracee Rego rule that detects when a container accesses the Docker socket (docker.sock). It covers selecting the security_socket_connect event, extracting the remote_addr argument to match the socket name, composing rule metadata and event selectors, and validating the rule by running Tracee with a custom rules directory and a container that mounts /var/run/docker.sock.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
