You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Custom Falco rules for GRC_Claw
- rule: Unexpected Process in Gateway Containerdesc: Detect unexpected process execution in gateway podscondition: > container and container_name=gateway and spawned_process and not proc.name in (node, npm, gateway) and not proc.name in (container_privileged_procs)output: > Unexpected process in gateway (user=%user.name command=%proc.cmdline container=%container.id image=%container.image.repository)priority: CRITICALtags: [container, gateway, GRC_Claw]
- rule: Evidence Chain Tamperingdesc: Detect write attempts to evidence graph outside normal flowcondition: > container and container_name=evidence-writer and open_write and fd.name startswith /data/evidence and not proc.name in (node, postgres)output: > Evidence chain write outside normal flow (file=%fd.name process=%proc.name container=%container.id)priority: CRITICALtags: [evidence, tampering, GRC_Claw]
- rule: Anomalous Outbound Connectiondesc: Detect unexpected outbound network connections from SOC podscondition: > container and outbound and not fd.sip.name in (allowed_destinations) and container_namespace=grc-clawoutput: > Anomalous outbound connection (dest=%fd.rip container=%container.id process=%proc.name)priority: HIGHtags: [network, anomaly, GRC_Claw]
interfaceExecPolicy{policyId: string;tenantId: string;rules: ExecPolicyRule[];enforcement: 'enforce'|'audit'|'disabled';metadata: {version: number;effectiveFrom: string;// ISO 8601effectiveTo: string;// ISO 8601approvedBy: string;// User ID};}interfaceExecPolicyRule{ruleId: string;action: 'allow'|'deny'|'challenge';targets: {principal?: string;// User or service accountresource?: string;// API endpoint or resource patternaction?: string;// HTTP method or operationconditions?: Record<string,unknown>;// Context-dependent};priority: number;// Higher = evaluated firsteffect: 'permit'|'deny';}
Separation of Duties (SoD)
Critical operations require multi-party approval:
- Evidence chain deletion: 2 of 3 SOC leads
- Policy changes: SOC lead + Compliance officer
- Connector credential rotation: DevOps + Security
- Tenant data export: Tenant admin + Data protection officer
Implementation:
- Approval workflow with timeout (24h)
- Cryptographic attestation of approvals
- Audit trail in evidence graph
- SoD violations blocked at policy firewall
Canary Traps
// Honeypot credentials embedded in production systemsinterfaceCanaryTrap{trapId: string;type: 'credential'|'data'|'endpoint'|'file';value: string;// The canary value (e.g., fake API key)alertOn: 'read'|'write'|'use'|'all';severity: 'critical';// Any use = critical incidentdecoy: {description: string;// What this appears to belocation: string;// Where it's planted};response: {notify: string[];// Email/Slack channelsautoBlock: boolean;// Auto-block source IPpreserveForensics: boolean;// Snapshot state before blocking};}// Types of canary traps:// 1. Fake AWS credentials in environment files// 2. Decoy database entries with tracking markers// 3. Fake API endpoints that log all access// 4. Canary tokens in exported reports
Behavioral Anomaly Detection
Baseline Learning Phase (14 days):
- Normal access patterns per user/service
- Typical API call volumes and endpoints
- Expected data access scopes
- Standard working hours
Detection Rules:
1. Access from new IP/geo → Step-up auth
2. API call volume >3σ from baseline → Rate limit + alert
3. Access to resources outside normal scope → Block + alert
4. Off-hours access to critical systems → Challenge + alert
5. Rapid sequential resource access (scraping) → Block + alert
6. Authentication failures >5 in 5min → Lock account + alert
7. Service account behaving like human user → Alert + investigate
Response Actions:
- Alert via SIEM integration
- Evidence node created in graph
- Automatic policy adjustment (temporary blocks)
- Forensic snapshot of session