Skip to main content

Falco

Falco is a cloud-native security tool designed for Linux systems.
It employs custom rules on kernel events, which are enriched with container and Kubernetes metadata, to provide real-time alerts.

🌐 falco.org (falcosecurity/falco)

📝 falco.org/docs, sysdig.com/opensource/falco

Architecture

Falco architecture diagram

Getting started

Presentation

Releases

VersionDateLinks
0.15May 13th, 2019sysdig blog

Web resources

Readings

Web recordings