Falco - Open Source Docker Security - WTF my container just spawned a shell

Опубликовано: 25 Июль 2026
на канале: Sysdig
2,665
16

Falco is an open source container security solution designed for behavioral anomaly activity detection. With Falco you can continuously monitor and detect container, application, host and network activity... all in one place, from one source of data, with custom rules.

Watch this and we'll show how you can set up easy up customer rules with Sysdig Falco for detecting security breaches such as detecting if a container spawns a shell.

For more information about Falco, visit https://falco.org/

To see how Sysdig uses Falco, go to https://www.sysdig.com/falco/


Mark Stemm (mstemm - GitHub) is a Software Engineer with 20 years experience using data and analysis to solve hard problems and build great products. He has a B.S. in Mathematics/Computer Science from Carnegie Mellon University and a M.S. and Ph.D. in Computer Science from the University of California, Berkeley. He's worked at Fast Forward Networks/Inktomi on the first generation of internet-based live video broadcasting, at Cloudmark building the world's leading email anti-spam platform for ISPs and mobile providers, and at Jut building a streaming data analysis and visualization platform. Mark currently works at Sysdig on the open source product Falco, a behavioral activity monitor with full support for containers.