
Falco
Falco is a free open-source runtime security tool used to detect suspicious behavior in hosts, containers, and Kubernetes in real time for cloud security teams.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- Linux
- License
- Open source
- Reviewed
- Last reviewed 10 October 2026
What it is
A detection engine that watches Linux kernel events through eBPF, matches them against rules, and adds context such as container and pod details before raising an alert. Plugins let it read other event sources too.
What it helps with
- Catching unexpected configuration changes and attacks at runtime
- Watching cloud audit logs such as AWS CloudTrail
- Streaming alerts to other tools for real-time response
- Supporting compliance monitoring with rule-based detection
Who it's for
Cloud, platform, and security operations teams protecting the hosts and clusters they run.
Worth knowing
It is a graduated Cloud Native Computing Foundation project. Detection is streaming, so it alerts as events happen rather than storing data to search later.
Can I write my own rules?
Yes, custom rules are a core part of how it works.
Does it block attacks?
No, it detects and alerts, and responses are handled by the tools you connect it to.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.