Kai Ole Hartwig

name of the term: Tetragon
descriptions of the term:

Definition

Definition. An eBPF-based component from the Cilium project for runtime observability and policy enforcement in the Linux kernel. Tetragon records process, file and network activity close to the kernel, can block actions synchronously and works with the Cilium CNI on a shared eBPF data plane.

Why it matters. While Falco traditionally focuses on “detect and alert”, Tetragon can also handle enforcement. This matters for setups in which runtime violations should not just be logged but stopped.

Related. Falco, Runtime Security, Threat Detection, Container Escape

Type of term: definition
Language of the term (2 char ISO code): en
Back