Falco can detect and alert on any behaviour that makes Linux system calls. The alerting rules make use of Sysdig's filtering expressions to identify potentially suspicious activity. Alerts can be triggered on the use of specific system calls, the arguments to those calls, and by the properties of the calling process. This includes scenarios such as a process starting a shell inside a container, a container running in privileged mode, or an unexpected read of a sensitive file. In the event of a detection, Falco can notify via Slack, Fluentd, and NATS.
The Falco workshop is ideal for:
- Website owners who are struggling to get traffic and sales
