falcosecurity / rules
Falco rule repository
☆118Updated this week
Alternatives and similar repositories for rules:
Users that are interested in rules are comparing it to the libraries listed below
- Falco plugins registry☆92Updated last week
- Generate a variety of suspect actions that are detected by Falco rulesets☆103Updated last month
- Response Engine for managing threats in your Kubernetes☆154Updated last week
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆81Updated last year
- Runtime detection and response for malicious events in Kubernetes workloads☆43Updated last year
- Community curated list of System and Network policy templates for the KubeArmor and Cilium☆43Updated 3 weeks ago
- The Falco Project Community☆55Updated 3 weeks ago
- Administrative tooling for Falco☆98Updated last week
- A simple WebUI with latest events from Falco☆119Updated this week
- Connect Falco to your ecosystem☆584Updated this week
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- Process documentation, non-code deliverables, and miscellaneous artifacts of Kubernetes SIG Security☆202Updated 2 weeks ago
- Kubernetes audit logging, when you don't control the control plane☆73Updated last week
- Evaluate the RBAC permissions of Kubernetes identities through policies written in Rego☆343Updated 3 weeks ago
- Prometheus Metrics Exporter for Falco output events☆122Updated last month
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆125Updated this week
- Create Kubernetes AdmissionReview requests from Kubernetes resource manifests☆146Updated 2 weeks ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆82Updated 3 months ago
- Runtime security plug to protect user containers☆65Updated last month
- ☆94Updated 2 months ago
- Use Trivy as a plug-in vulnerability scanner in the Harbor registry☆221Updated 7 months ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- agent for handling seccomp descriptors for container runtimes☆46Updated last year
- OCI hook to trace syscalls and generate a seccomp profile☆319Updated 2 weeks ago
- Curating Falco rules with MITRE ATT&CK Matrix☆78Updated last year
- AI-generated remediations for Falco audit events☆70Updated last year
- A replacement for "kubectl exec" that works over WebSocket connections.☆38Updated last year
- Damn Vulnerable Kubernetes App (DVKA) is a series of apps deployed on Kubernetes that are damn vulnerable.☆138Updated 2 weeks ago
- book website☆68Updated 3 years ago
- ptrace-based event producer for udig☆67Updated 2 years ago