Sysdig Site Search
MITRE ATT&CK framework for container runtime security with Falco.
MITRE ATT&CK is a comprehensive knowledge base and complex framework of over 200 techniques that adversaries may use over the...
Falco in the open
One of the most successful aspects of Kubernetes is how functional the open source community was able to operate. Kubernetes...
Detecting CVE-2020-14386 with Falco and mitigating potential container escapes
On Sept. 14, CVE-2020-14386 was reported as a “high” severity threat. This CVE is a kernel security vulnerability that enables...
Detect CVE-2020-8557 using Falco
A new vulnerability, CVE-2020-8557, has been detected in kubelet. It can be exploited by writing into /etc/hosts to cause a...
Detecting jQuery File Upload vulnerability using Falco (CVE-2018-9206)
In the past few days, a new vulnerability was disclosed in a widely used component – jQuery File Upload plugin....
Preventing DoS Kubernetes using Falco and Calico
A Denial-of-Service (DoS) is an attack meant to shut down a machine or network, making it inaccessible to its intended...
Breaking down firewalls with BPFDoor (no e!) – How to detect it with Falco
BPF (not eBPF), typically viewed from a defender/sysadmin’s perspective, provides easy access to network packets and the ability to take...
Kubernetes is a beast: Tame its security related events (using Falco based rules with Sysdig Secure runtime policies) – EMEA
In this webinar, we will showcase how Sysdig Secure can simplify Kubernetes security by providing out-of-the-box policies and easily digestible events. We will also present a use-case based on the daily administration effort that Kubernetes specialists face and how Sysdig Secure (using Falco) can enable effective security on Kubernetes
Detect threats in real time with Falco on AWS
The ultimate line of defense is runtime security. Falco is the open source runtime security solution for threat detection across containers, hosts, Kubernetes and the cloud.
How to mitigate CVE-2021-33909 Sequoia with Falco – Linux filesystem privilege escalation vulnerability
The CVE-2021-33909, named Sequoia, is a new privilege escalation vulnerability that affects Linux’s file system. It was disclosed in July,...