Falco logo Falco logo background glow

Falco

A tool that monitors system calls and container events to identify deviations in system behavior and generate alerts to log changes

It takes care to curate a safe software space. Help us do more.

&

+
Real-time Event Monitoring
Captures system calls and process events as they occur; enables detection of system changes as they happen.
+
Linux Kernel Monitoring
Observes Linux kernel events through system call tracing to identify activities that differ from defined behavior patterns
+
Rule-based Detection Engine
Evaluates events against rules written in YAML; allows users to define detection logic based on their environment.
+
Container Security Integration
Observes activities within containerized environments; monitors container metadata alongside system events to detect deviations from expected container activity
+
Plugin Architecture
Supports integration with plugins that connect external data sources, thereby expanding the scope of monitored events
+
Cloud-native Support
Integrates with Kubernetes and similar platforms; supports monitoring in distributed system setups.
+
Log Generation
Stores event data over time so that past system activity can be reviewed at a later time.
+
Integration with SIEM Tools
Supports output formats compatible with SIEM systems; helps centralize security events for analysis.
+
Kubernetes Audit Monitoring
Reads Kubernetes audit logs to capture cluster activity; assists in monitoring actions within Kubernetes clusters.
...16 more features/limitations. Contact us to get a complete list of features and system requirements.

Platform

Desktop

Social

System Requirements

Not available, but we appreciate help! You can help us improve this page by contacting us.

Ratings

Not available, but we appreciate help! You can help us improve this page by contacting us.

Developer

Written in

C++, C, CMake

Initial Release

2016-05-18

Repository

License

Categories