diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index d2f8a129e55..a7fc23adacd 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -830,7 +830,7 @@ condition: (never_true) - rule: Write below monitored dir - desc: an attempt to write to any file below a set of binary directories + desc: an attempt to write to any file below a set of monitored directories condition: > evt.dir = < and open_write and monitored_dir and not exe_running_docker_save