source: kubearmor-dev
cmd: head -n 1 /etc/passwd
result: passed 
---
operation: File
condition: /etc/passwd
action: Audit
