Controlled shell detected SELECTED VISIBLE OUTPUT — not a full log Selected visible output: uid=10001(appuser) gid=10001(appgroup) groups=10001(appgroup) "priority": "Critical" "rule": "Shell Spawned In Signed Workload Pod" Critical Unexpected shell spawned in hardened pod user=appuser ns=default cmdline=sh -c id RESULT: PASS - Falco detected the controlled runtime shell Original: https://github.com/devSatym/gcp-supply-chain-security/blob/cbbc807c0c150e106affa89fbb1b9e8349005749/docs/my-validation/12-falco-runtime.png Limitations: - Detection happened after successful shell execution; no prevention or automatic termination observed. - The rule condition does not verify signatures. - The captured image tag does not establish a manifest digest or build commit. - No external notification or incident-response completion captured.