diff --git a/falco/rules/miner-pool-ports.yaml b/falco/rules/miner-pool-ports.yaml index fb8fb9a..c91463a 100644 --- a/falco/rules/miner-pool-ports.yaml +++ b/falco/rules/miner-pool-ports.yaml @@ -15,11 +15,20 @@ # removed. items: [3333, 3334, 4444, 5555, 5556, 7777, 8888, 9999, 14444] +# Loopback exclusion added 2026-08-25: some unidentified host-level process +# connects to ::1:8888 roughly once a day (confirmed 5x over 2026-08-20 to +# 2026-08-25, always ~21:3x, always container=host, always failing instantly +# since nothing listens on 8888 - falco loses process metadata for it before +# it can be identified). A real mining pool is by definition a remote +# server, so loopback destinations can never be genuine pool traffic - this +# is a false positive in the rule's design (any port 8888 connection, not +# just remote ones), not a tuned-out exception for a known process. - rule: Detect outbound connection to common miner pool port desc: Outbound connection to a TCP port commonly used by cryptomining pools. condition: > outbound and evt.type in (connect, sendto, sendmsg) and fd.rport in (miner_pool_ports) + and not (fd.rip in ("127.0.0.1", "::1")) output: > Outbound connection to common miner-pool port (user=%user.name command=%proc.cmdline connection=%fd.name