OSS Tanbou

detect abnormal Linux, container, and Kubernetes runtime behavior in real time with rule-based kernel event monitoring

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
9,438
Primary language
C++
License
Apache-2.0
Repository last updated
Oct 3, 2026
On this page

Overview

Falco is a cloud-native runtime security tool for Linux. It observes kernel events such as syscalls, evaluates them against rules, and alerts on abnormal behavior and potential threats. Container-runtime and Kubernetes metadata can enrich events before they are forwarded to systems such as SIEMs or data lakes.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Continuously evaluate kernel events against detection rules

Falco acts as a kernel monitoring and detection agent, observing events such as syscalls and alerting when behavior matches configured rules.

Sources: [1]

Add container and Kubernetes context to runtime events

Events can be enriched with container-runtime and Kubernetes metadata so investigations retain workload context. Collected events can also be analyzed off-host in SIEM or data-lake systems.

Sources: [1]

Operate through a modular rules, plugins, and deployment ecosystem

The Falco project separates the core binary from official rules, plugins, falcoctl, and Helm charts, allowing detection content, external event sources, and Kubernetes deployment concerns to evolve independently.

Sources: [1]

Best fit

Fits teams adding runtime detection to Linux and Kubernetes environments

It is useful when teams need rule-based monitoring of live Linux workloads, including containers and Kubernetes, and want to route detections into an existing incident-response workflow.

Sources: [1]

Before adoption

Validate kernel and event-capture compatibility before production deployment

Because Falco depends on Linux kernel events, validate environment compatibility, detection goals, performance, and the selected build or driver before rollout. The README explicitly recommends these checks for production deployments.

Sources: [1]

0.45.0 includes a breaking rule-evaluation change

Version 0.45.0 evaluates rule conditions on raw field bytes and bumps the Falco Engine version to 0.63.0. Some existing rules require review, so upgrades should start with the release CHANGELOG.

Sources: [2]

Official sources

  1. [1]Falco 0.45.0 README(2026-10-04)
  2. [2]Falco 0.45.0 CHANGELOG(2026-10-04)
  3. [3]Falco 0.45.0 release(2026-10-04)
  4. [4]Falco Apache-2.0 license(2026-10-04)
Supplemental curator note

Falco delivers the most value when detection rules, alert routing, and incident-response workflows are designed together rather than treating the engine as a standalone sensor. Version 0.45.0 includes a breaking rule-evaluation change, so existing rules should be reviewed before upgrading.

Try it in 3 steps

  1. 1

    Fetch the Falco 0.45.0 demo configuration

    Clone the repository at the 0.45.0 tag. The bundled demo is intended for evaluation on a Linux host.

    git clone --depth 1 --branch 0.45.0 https://github.com/falcosecurity/falco.git falco-0.45.0
  2. 2

    Inspect the Docker Compose configuration before running it

    The official demo gives Falco visibility into host paths such as /proc and /etc and the Docker socket. Review the expanded configuration first.

    cd falco-0.45.0/docker/docker-compose && docker-compose config
  3. 3

    Start the demo stack

    Run this only on a Linux development or evaluation host, then open http://127.0.0.1:2802. The upstream README explicitly states that this Compose setup is not production-ready.

    cd falco-0.45.0/docker/docker-compose && docker-compose up
Check the official README

Growth

Growth trends · Last 30 days

9,438 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
58
Open PRs
19

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • cncf
  • containers
  • security
  • falco
  • ebpf
  • kubernetes
  • hacktoberfest
  • cloud-native
  • cncf-project
  • runtime-security
Stars
9,438
Forks
1,084
Watchers
131
Open issues
28
Contributors
233
Owner type
Organization
Primary language
C++
License
Apache-2.0
Repository last updated
Oct 3, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?