ECS Fargate PV 1.4 SYS_PTRACE Demo
Based on https://github.com/kris-nova/falco-trace
- Task Definition Name:
ecs-ptrace-falcoserver
- Image:
registry.hub.docker.com/paavanmistry/ecs-ptrace-falcoserver:latest
- Add json
"linuxParameters": {
"capabilities": {
"add": [
"SYS_PTRACE"
],
"drop": null
}
},
- Run
curl ifconfig.me
- Connect and run
touch /usr/bin/1
,cat /etc/shadow
, andtouch /etc/backdoor