falcosecurity / rules
Falco rule repository
☆107Updated this week
Alternatives and similar repositories for rules:
Users that are interested in rules are comparing it to the libraries listed below
- Falco plugins registry☆87Updated this week
- Generate a variety of suspect actions that are detected by Falco rulesets☆101Updated this week
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆80Updated last year
- Response Engine for managing threats in your Kubernetes☆148Updated this week
- Runtime detection and response for malicious events in Kubernetes workloads☆41Updated 11 months ago
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆123Updated this week
- Evaluate the RBAC permissions of Kubernetes identities through policies written in Rego☆343Updated last year
- The Falco Project Community☆53Updated 3 weeks ago
- Trivy's misconfiguration scanning engine☆218Updated 3 weeks ago
- Administrative tooling for Falco☆91Updated this week
- Community curated list of System and Network policy templates for the KubeArmor and Cilium☆42Updated 2 weeks ago
- A simple WebUI with latest events from Falco☆117Updated this week
- Prometheus Metrics Exporter for Falco output events☆121Updated 2 months ago
- Threat-informed defense for cloudnative: Reference Implementation of a so-called Honeycluster - for kind (and GKE, RKE2, AKS)☆30Updated this week
- Process documentation, non-code deliverables, and miscellaneous artifacts of Kubernetes SIG Security☆184Updated 2 weeks ago
- Create Kubernetes AdmissionReview requests from Kubernetes resource manifests☆113Updated last month
- Connect Falco to your ecosystem☆567Updated this week
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- ☆175Updated 3 months ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆79Updated last month
- Kubernetes audit logging, when you don't control the control plane☆67Updated this week
- ☆92Updated 2 weeks ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities☆101Updated 4 months ago
- book website☆67Updated 3 years ago
- Kubernetes focused container assessment and context discovery tool for penetration testing☆448Updated 8 months ago
- Runtime security plug to protect user containers☆65Updated this week
- Curating Falco rules with MITRE ATT&CK Matrix☆77Updated 11 months ago
- agent for handling seccomp descriptors for container runtimes☆44Updated last year
- Tool for building Kubernetes attack paths☆818Updated last week