Falco

E703664

Falco is an open-source cloud-native runtime security tool that monitors system behavior to detect and alert on suspicious activity in containers, Kubernetes, and Linux hosts.

All labels observed (1)

Label Occurrences
Falco canonical 4

How this entity was disambiguated

Statements (47)

Predicate Object
instanceOf behavior-based security tool ⓘ
cloud-native security project ⓘ
intrusion detection system ⓘ
open-source software ⓘ
runtime security tool ⓘ
alertsOn suspicious activity in Kubernetes ⓘ
suspicious activity in containers ⓘ
suspicious activity on Linux hosts ⓘ
analyzes container runtime activity ⓘ
file system activity ⓘ
kernel-level events ⓘ
network activity ⓘ
process activity ⓘ
category cloud-native runtime security tool ⓘ
open-source security project ⓘ
coreCapability behavioral monitoring ⓘ
policy-based alerting ⓘ
real-time threat detection ⓘ
deploymentModel agent-based ⓘ
designedFor Kubernetes clusters ⓘ
linked to: Kubernetes

cloud-native environments ⓘ
containerized workloads ⓘ
detects anomalous behavior ⓘ
security threats at runtime ⓘ
suspicious activity ⓘ
domain Kubernetes security ⓘ
Linux security ⓘ
cloud security ⓘ
container security ⓘ
license open-source license ⓘ
monitors Kubernetes workloads ⓘ
Linux hosts ⓘ
Linux system calls ⓘ
containers ⓘ
system behavior ⓘ
purpose detect policy violations ⓘ
improve runtime security of cloud-native workloads ⓘ
provide security alerts ⓘ
softwareType intrusion detection ⓘ
runtime security ⓘ
threat detection ⓘ
sourceModel open source ⓘ
supportsPlatform Docker ⓘ
Kubernetes ⓘ
Linux ⓘ
uses rules engine ⓘ
security policies ⓘ

How these facts were elicited

Referenced by (4)

Full triples — surface form annotated when it differs from this entity's canonical label.