Falco rule repository
☆173Jun 3, 2026Updated last week
Alternatives and similar repositories for rules
Users that are interested in rules are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆307Updated this week
- Falco plugins registry☆116Jun 3, 2026Updated last week
- Administrative tooling for Falco☆128Jun 1, 2026Updated last week
- A crawler for kernel releases distributed by the major Linux distributions.☆13Oct 18, 2024Updated last year
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆89Jan 28, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Generate a variety of suspect actions that are detected by Falco rulesets☆120May 22, 2026Updated 2 weeks ago
- Prometheus Metrics Exporter for Falco output events☆121Apr 16, 2025Updated last year
- Response Engine for managing threats in your Kubernetes☆201May 15, 2026Updated 3 weeks ago
- Curating Falco rules with MITRE ATT&CK Matrix☆87Mar 7, 2024Updated 2 years ago
- Cloud Native Runtime Security☆9,019Jun 1, 2026Updated last week
- Connect Falco to your ecosystem☆667Updated this week
- Fetches the metadata from kubernetes API server and dispatches them to Falco instances☆22Jun 4, 2026Updated last week
- ☆18Jul 17, 2024Updated last year
- Demo repository for running eBPF in GitHub Actions☆23Mar 27, 2025Updated last year
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A simple WebUI with latest events from Falco☆138Updated this week
- Community managed Helm charts for running Falco with Kubernetes☆292Jun 3, 2026Updated last week
- ☆12Jul 8, 2023Updated 2 years ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆70May 7, 2026Updated last month
- 内存加载执行golang elf二进制文件☆29Dec 22, 2021Updated 4 years ago
- Sublime rules for email attack detection, prevention, and threat hunting.☆364Updated this week
- The high-level/low-level implementation of Linux Fanotify.☆26Nov 11, 2025Updated 7 months ago
- Kubernetes focused container assessment and context discovery tool for penetration testing☆481Nov 7, 2025Updated 7 months ago
- Nginx Multi Cluster Ingress Controller (based on kubernetes/ingress-nginx@v1.1.1)☆20Feb 28, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Detect intrusions that happened in your Kubernetes cluster through audit logs using Falco☆63Jun 2, 2021Updated 5 years ago
- the ps utility, with an eBPF twist and container context☆296Jan 16, 2026Updated 4 months ago
- ☆10Apr 19, 2026Updated last month
- eBPF-based Security Observability and Runtime Enforcement☆4,739Updated this week
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆219May 24, 2026Updated 2 weeks ago
- Demonstrating how you can take an action to your intrusions detected by Falco using OpenFaaS functions☆26Mar 24, 2021Updated 5 years ago
- Example program using eBPF to log data being based in using shell pipes☆41Feb 15, 2021Updated 5 years ago
- Evolution process of The Falco Project☆62Updated this week
- Tool for building Kubernetes attack paths☆973Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A tool for in-depth analysis of container checkpoints☆148Apr 22, 2026Updated last month
- exploit-db备份☆15Jan 5, 2022Updated 4 years ago
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆232May 26, 2025Updated last year
- Fluent input plugin for MySQL slow query log file.☆22Dec 22, 2018Updated 7 years ago
- A simple example of map_in_map usage in libbpf☆10Mar 18, 2020Updated 6 years ago
- A C and Go /proc/pid/maps cloak of invisibilty for shared object files☆22Nov 19, 2025Updated 6 months ago
- Quick script to build host or investigation timelines using Carbon Black Response☆12Sep 25, 2018Updated 7 years ago