diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index beae1603931..04ac475d958 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -1685,7 +1685,8 @@ mesos_shell_binaries, erl_child_setup, exechealthz, PM2, PassengerWatchd, c_rehash, svlogd, logrotate, hhvm, serf, - lb-controller, nvidia-installe, runsv, statsite, erlexec) + lb-controller, nvidia-installe, runsv, statsite, erlexec, calico-node, + "puma reactor") and not proc.cmdline in (known_shell_spawn_cmdlines) and not proc.aname in (unicorn_launche) and not consul_running_net_scripts