Falco
A tool that monitors system calls and container events to identify deviations in system behavior and generate alerts to log changes
It takes care to curate a safe software space. Help us do more.
&
| + | Real-time Event Monitoring | Captures system calls and process events as they occur; enables detection of system changes as they happen. |
|---|---|---|
| + | Linux Kernel Monitoring | Observes Linux kernel events through system call tracing to identify activities that differ from defined behavior patterns |
| + | Rule-based Detection Engine | Evaluates events against rules written in YAML; allows users to define detection logic based on their environment. |
| + | Container Security Integration | Observes activities within containerized environments; monitors container metadata alongside system events to detect deviations from expected container activity |
| + | Plugin Architecture | Supports integration with plugins that connect external data sources, thereby expanding the scope of monitored events |
| + | Cloud-native Support | Integrates with Kubernetes and similar platforms; supports monitoring in distributed system setups. |
| + | Log Generation | Stores event data over time so that past system activity can be reviewed at a later time. |
| + | Integration with SIEM Tools | Supports output formats compatible with SIEM systems; helps centralize security events for analysis. |
| + | Kubernetes Audit Monitoring | Reads Kubernetes audit logs to capture cluster activity; assists in monitoring actions within Kubernetes clusters. |
...16 more features/limitations. Contact us to get a complete list of features and system requirements.
System Requirements
Not available, but we appreciate help! You can help us improve this page by contacting us.
Ratings
Not available, but we appreciate help! You can help us improve this page by contacting us.