falcosecurity / rules
Falco rule repository
☆122Updated last week
Alternatives and similar repositories for rules:
Users that are interested in rules are comparing it to the libraries listed below
- Falco plugins registry☆94Updated this week
- Generate a variety of suspect actions that are detected by Falco rulesets☆105Updated last month
- Runtime detection and response for malicious events in Kubernetes workloads☆44Updated last year
- Response Engine for managing threats in your Kubernetes☆159Updated last week
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆81Updated last year
- Administrative tooling for Falco☆104Updated this week
- Curating Falco rules with MITRE ATT&CK Matrix☆79Updated last year
- Red Canary's eBPF Sensor☆105Updated 10 months ago
- Process documentation, non-code deliverables, and miscellaneous artifacts of Kubernetes SIG Security☆204Updated last month
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆125Updated 3 weeks ago
- A simple WebUI with latest events from Falco☆120Updated 3 weeks ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆84Updated 4 months ago
- Trivy's misconfiguration scanning engine☆218Updated 3 months ago
- AI-generated remediations for Falco audit events☆71Updated last year
- Community curated list of System and Network policy templates for the KubeArmor and Cilium☆44Updated last month
- 🧰 Multi Tool Kubernetes Pentest Image☆230Updated 3 weeks ago
- Evaluate the RBAC permissions of Kubernetes identities through policies written in Rego☆344Updated last month
- ☆177Updated 2 weeks ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated last week
- Create Kubernetes AdmissionReview requests from Kubernetes resource manifests☆148Updated last week
- Prometheus Metrics Exporter for Falco output events☆122Updated 3 weeks ago
- ☆86Updated last month
- The Falco Project Community☆55Updated last month
- ☆96Updated 3 months ago
- A replacement for "kubectl exec" that works over WebSocket connections.☆38Updated last year
- book website☆68Updated 3 years ago
- Runtime security plug to protect user containers☆65Updated last week
- Tool for building Kubernetes attack paths☆857Updated this week
- Leaky Vessels Dynamic Detector☆102Updated 3 weeks ago