Kai Ole Hartwig

name of the term: Falco
descriptions of the term:

Definition

Definition. An open source tool for runtime security on Linux and Kubernetes systems. Falco observes system calls (via a kernel module or eBPF), evaluates them against a rule set and reports suspicious activity, e.g. shells in containers, unexpected setuid calls or access to sensitive paths. The CNCF lists it as “Graduated”.

Why it matters. Falco is an established building block for threat detection in Kubernetes environments on an open source basis, without proprietary agent licences and with traceable rules.

Related. Tetragon, Runtime Security, Threat Detection, Container Escape

Type of term: definition
Language of the term (2 char ISO code): en
Back