In a Falco rule, you have the condition: 'evt.type=execve and proc.name=bash and container.id!=host'. What does this rule detect?
The condition matches execve system calls where the executed process is bash and the container ID is not the host, so it fires on shells spawned inside containers. This detects interactive or scripted bash execution within containerised workloads, not host-level bash.
Why this answer
The rule triggers when a bash shell is executed (execve) inside any container (container.id != host). It does not check for interactive use; it simply detects bash execution.