diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index 28cedc6a3de..f8d4950f336 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -1949,7 +1949,7 @@ desc: > Detect grep private keys or passwords activity. condition: > - (spawned_process and container and + (spawned_process and ((grep_commands and private_key_or_password) or (proc.name = "find" and (proc.args contains "id_rsa" or proc.args contains "id_dsa"))) )