Container Runtime Security Falco

Runtime threat detection with Falco and eBPF: custom rule authoring, syscall and Kubernetes audit sources, macros, lists and exceptions for tuning, alert routing, and response playbooks. Use when alerting on attacker behaviour inside a running container such as an interactive shell being opened in production, writing or tuning a noisy Falco rule, or triaging a runtime alert.

mchittineni 15e4d84 2 files · 5.8 KB Updated

File contents

mchittineni/cloud-platform-skills/tree/main/.agents/skills/container-runtime-security-falco commit 15e4d84ea2

Frequently asked questions

npx skillmds@latest add mchittineni/container-runtime-security-falco