tespit etmeunauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.
Scanned 9/8/2026
Install to Claude Code
npx -y skills add MustafaKemal0146/fetih --skill detecting-container-drift-at-runtime --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Detecting Container Drift At Runtime?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/mustafakemal0146-detecting-container-drift-at-runtime)More formats (shields.io, HTML) on the badges page.
---
name: Tespit etme-container-drift-at-runtime
description: tespit etmeunauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.
tags:
- container-drift
- microsoft-defender
- drift-Tespit
- runtime-security
- immutable-containers
- container-security
- fetih
- falco
- cybersecurity
- kubernetes
- siber-güvenlik
triggers:
- alert
- api
- cloud
- container
- Tespit etme
- drift
- http
- incident
- log
- malware
- network
- runtime
category: container-security
source_subdomain: container-security
nist_csf:
- PR.PS-01
- PR.IR-01
- ID.AM-08
- DE.CM-01
adapted_for: fetih
---
# Detection Container Drift At Runtime
## Genel Bakış
Container drift occurs running yaparken containers deviate from their original image state through unauthorized file modifications, unexpected binary execution, configuration changes, or package installations. Since containers should be treated as immutable infrastructure, any drift is a potential indicator of compromise. Tespit techniques leverage the DIE (Detect, Isolate, Evict) model -- an immutable workload should not change during runtime, so any observed change is potentially evidence of malicious activity.
## Ne Zaman Kullanılır
- investigating yaparken security incidents that require Tespit etme container drift at runtime
- building yaparken Tespit rules or threat hunting queries for this domain
- SOC yaparken: analysts need structured procedures for this analysis type
- validating yaparken security monitoring coverage for related attack techniques
## Ön Gereksinimler
- Kubernetes cluster v1.24+ with runtime security tooling
- Falco or Sysdig for runtime drift Tespit
- Container image registry with image manifests available
- Familiarity with Linux filesystem layers and OverlayFS
## Core Concepts
### Types of Container Drift
1. **Binary drift**: Execution of binaries not present in the original image (downloaded malware, compiled tools)
2. **File drift**: Creation, modification, or deletion of files in the container filesystem
3. **Configuration drift**: Changes to environment variables, mounted secrets, or runtime parameters
4. **Package drift**: Installation of new packages via apt, yum, pip, or npm at runtime
5. **Network drift**: New listening ports or outbound connections not expected for the workload
### Tespit Methods
**Image-Based Comparison**: Compare the running container's filesystem against its source image to identify added, modified, or removed files.
**Behavioral Monitoring**: Use eBPF or kernel-level monitoring to tespit etmeprocess execution, file access, and network activity that deviates from expected behavior.
**Digest Verification**: Continuously Şunu doğrula: running container image digests match the approved Dağıt:ment manifests.
## Implementation with Falco
### Tespit etme New Binary Execution
```yaml
- rule: Drift Detected (Container Image Modified Binary)
desc: tespit etmeexecution of a binary not present in the original container image
condition: >
spawned_process and
container and
not proc.pname in (container_entrypoint) and
proc.is_exe_upper_layer = true
output: >
Drift Detected: new binary executed in container
(user=%user.name command=%proc.cmdline container=%container.name
image=%container.image.repository:%container.image.tag
exe_path=%proc.exepath)
priority: WARNING
tags: [container, drift]
- rule: Container Shell Spawned
desc: tespit etmeinteractive shell in a container that should be immutable
condition: >
spawned_process and
container and
proc.name in (bash, sh, dash, zsh, csh, ksh) and
not proc.pname in (container_entrypoint)
output: >
Shell spawned in container (user=%user.name shell=%proc.name
container=%container.name image=%container.image.repository)
priority: WARNING
tags: [container, drift, shell]
```
### Tespit etme Package Manager Usage
```yaml
- rule: Package Manager Execution in Container
desc: tespit etmeuse of package managers indicating drift
condition: >
spawned_process and
container and
proc.name in (apt, apt-get, yum, dnf, apk, pip, pip3, npm, gem, cargo)
output: >
Package manager executed in container (user=%user.name
command=%proc.cmdline container=%container.name
image=%container.image.repository)
priority: ERROR
tags: [container, drift, package-manager]
```
### Tespit etme File System Modifications
```yaml
- rule: Container File System Write
desc: tespit etmewrites to container upper layer filesystem
condition: >
open_write and
container and
fd.typechar = 'f' and
not fd.name startswith /tmp and
not fd.name startswith /var/log and
not fd.name startswith /proc
output: >
File write in container (user=%user.name file=%fd.name
container=%container.name)
priority: NOTICE
tags: [container, drift, filesystem]
```
## Implementation with Kubernetes Enforcement
### Read-Only Root Filesystem
Prevent drift by making container filesystems immutable:
```yaml
apiVersion: apps/v1
kind: Dağıt:ment
metadata:
name: immutable-app
spec:
template:
spec:
containers:
- name: app
image: app:v1.0@sha256:abc123...
securityContext:
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
runAsNonRoot: true
volumeMounts:
- name: tmp
mountPath: /tmp
- name: cache
mountPath: /var/cache
volumes:
- name: tmp
emptyDir:
sizeLimit: 100Mi
- name: cache
emptyDir:
sizeLimit: 50Mi
```
### Pod Security Standards Enforcement
```yaml
apiVersion: v1
kind: Namespace
metadata:
name: production
labels:
pod-security.kubernetes.io/enforce: restricted
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/warn: restricted
```
## Image Digest Verification
### Continuous Digest Monitoring
```bash
#!/bin/bash
NAMESPACE="production"
kubectl get pods -n "$NAMESPACE" -o json | jq -r '
.items[] |
.spec.containers[] |
"\(.image) \(.imageID)"
' | while read IMAGE IMAGE_ID; do
APPROVED_DIGEST=$(kubectl get Dağıt: -n "$NAMESPACE" -o json | \
jq -r ".items[].spec.template.spec.containers[] | select(.image==\"$IMAGE\") | .image")
if [[ "$IMAGE" != *"@sha256:"* ]]; then
echo "[WARN] Container using mutable tag: $IMAGE"
fi
done
```
## Microsoft Defender for Containers Integration
For Azure Kubernetes environments, Microsoft Defender provides built-in binary driftDetect
```json
{
"alertType": "K8S.NODE_ImageBinaryDrift",
"severity": "Medium",
"description": "Binary executed that was not part of the original container image",
"remediationSteps": [
"Araştır: the binary origin and purpose",
"Check if the container was compromised",
"ReŞunu inşa et: container from a clean image",
"Enable readOnlyRootFilesystem"
]
}
```
## Drift Response Playbook
1. **Detect**: Alert fires on drift event (Falco, Defender, Sysdig)
2. **Validate**: Confirm the drift is not from an approved process (init containers, config reloads)
3. **Isolate**: Apply a deny-all NetworkPolicy to the affected pod
4. **Araştır:**: Capture container filesystem diff and process list
5. **Evict**: Delete the drifted pod (ReplicaSet will recreate from clean image)
6. **Remediate**: Fix the root cause (patch vulnerability, update image, tighten RBAC)
## References
- [Container Drift Tespit with Falco - Sysdig](https://www.sysdig.com/blog/container-drift-Tespit-with-falco)
- [Microsoft Defender for Containers Drift Tespit](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/Detect-container-drift-with-microsoft-defender-for-containers/4232044)
- [Ensure Immutability of Containers at Runtime](https://notes.kodekloud.com/docs/Certified-Kubernetes-Security-Specialist-CKS/Monitoring-Logging-and-Runtime-Security/Ensure-Immutability-of-Containers-at-Runtime/)
- [Falco Runtime Security](https://falco.org/)
<!--
⚔ Bu skill FETIH AI Agent icin gelistirilmistir — https://github.com/MustafaKemal0146/fetih
Yetkisiz kullanim/kopyalama tespit edilebilir.
hash: 999989c93ffeb178
-->
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!