CloudNativeRutimeSecurity.
Wattotalk?Joiusothe#falcochaelitheKuberetesSlack.
LatestreleasesReadthechagelog.
developmetstablerpmdebbiaryTheFalcoProject,origiallycreatedbySysdig,isaicubatigCNCFopesourcecloudativerutimesecuritytool.Falcomakesiteasytocosumekerelevets,aderichthoseevetswithiformatiofromKuberetesadtherestofthecloudativestack.FalcohasarichsetofsecurityrulesspecificallybuiltforKuberetes,Liux,adcloud-ative.Ifaruleisviolatediasystem,Falcowillsedaalertotifyigtheuseroftheviolatioaditsseverity.
IstalligFalcoIfyouwouldliketoruFalcoiproductiopleaseadheretotheofficialistallatioguide.
Kuberetes
ToolLikNoteHelmChartRepositoryTheFalcocommuityoffersregularhelmchartreleases.MiikubeTutorialTheFalcodriverhasbeebakeditomiikubeforeasydeploymet.KidTutorialRuigFalcowithkidrequiresadriverothehostsystem.GKETutorialWesuggestusigtheeBPFdriverforruigFalcooGKE.DevelopigFalcoisdesigedtobeextesiblesuchthatitcabebuiltitocloud-ativeapplicatiosadifrastructure.
FalcohasagRPCedpoitadaAPIdefiediprotobuf.TheFalcoProjectsupportsvariousSDKsforthisedpoit.
SDKs
LaguageRepositoryGocliet-goRustcliet-rsPythocliet-pyWhatcaFalcodetect?FalcocadetectadalertoaybehaviorthativolvesmakigLiuxsystemcalls.Falcoalertscabetriggeredbytheuseofspecificsystemcalls,theirargumets,adbypropertiesofthecalligprocess.Forexample,Falcocaeasilydetecticidetsicludigbutotlimitedto:
AshellisruigisideacotaierorpodiKuberetes.Acotaierisruigiprivilegedmode,orismoutigasesitivepath,suchas/proc,fromthehost.Aserverprocessisspawigachildprocessofauexpectedtype.Uexpectedreadofasesitivefile,suchas/etc/shadow.Ao-devicefileiswritteto/dev.Astadardsystembiary,suchasls,ismakigaoutboudetworkcoectio.AprivilegedpodisstartediaKuberetescluster.DocumetatioTheOfficialDocumetatioisthebestresourcetolearaboutFalco.
JoitheCommuityTogetivolvedwithTheFalcoProjectpleasevisitthecommuityrepositorytofidmore.
Howtoreachout?
Joithe#falcochaelotheKuberetesSlackJoitheFalcomailiglistReadtheFalcodocumetatioCotributigSeetheCONTRIBUTING.md.
SecurityAuditAthirdpartysecurityauditwasperformedbyCure53,youcaseethefullreporthere.
ReportigsecurityvulerabilitiesPleasereportsecurityvulerabilitiesfollowigthecommuityprocessdocumetedhere.
LiceseTermsFalcoislicesedtoyouudertheApache2.0opesourcelicese.



















评论