On this page
Overview
Falco is a cloud-native runtime security tool for Linux. It observes kernel events such as syscalls, evaluates them against rules, and alerts on abnormal behavior and potential threats. Container-runtime and Kubernetes metadata can enrich events before they are forwarded to systems such as SIEMs or data lakes.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Continuously evaluate kernel events against detection rules
Falco acts as a kernel monitoring and detection agent, observing events such as syscalls and alerting when behavior matches configured rules.
Sources: [1]
Add container and Kubernetes context to runtime events
Events can be enriched with container-runtime and Kubernetes metadata so investigations retain workload context. Collected events can also be analyzed off-host in SIEM or data-lake systems.
Sources: [1]
Operate through a modular rules, plugins, and deployment ecosystem
The Falco project separates the core binary from official rules, plugins, falcoctl, and Helm charts, allowing detection content, external event sources, and Kubernetes deployment concerns to evolve independently.
Sources: [1]
Best fit
Fits teams adding runtime detection to Linux and Kubernetes environments
It is useful when teams need rule-based monitoring of live Linux workloads, including containers and Kubernetes, and want to route detections into an existing incident-response workflow.
Sources: [1]
Before adoption
Validate kernel and event-capture compatibility before production deployment
Because Falco depends on Linux kernel events, validate environment compatibility, detection goals, performance, and the selected build or driver before rollout. The README explicitly recommends these checks for production deployments.
Sources: [1]
0.45.0 includes a breaking rule-evaluation change
Version 0.45.0 evaluates rule conditions on raw field bytes and bumps the Falco Engine version to 0.63.0. Some existing rules require review, so upgrades should start with the release CHANGELOG.
Sources: [2]
Official sources
- [1]Falco 0.45.0 README(2026-10-04)
- [2]Falco 0.45.0 CHANGELOG(2026-10-04)
- [3]Falco 0.45.0 release(2026-10-04)
- [4]Falco Apache-2.0 license(2026-10-04)
Supplemental curator note
Falco delivers the most value when detection rules, alert routing, and incident-response workflows are designed together rather than treating the engine as a standalone sensor. Version 0.45.0 includes a breaking rule-evaluation change, so existing rules should be reviewed before upgrading.
Try it in 3 steps
- 1
Fetch the Falco 0.45.0 demo configuration
Clone the repository at the 0.45.0 tag. The bundled demo is intended for evaluation on a Linux host.
git clone --depth 1 --branch 0.45.0 https://github.com/falcosecurity/falco.git falco-0.45.0 - 2
Inspect the Docker Compose configuration before running it
The official demo gives Falco visibility into host paths such as /proc and /etc and the Docker socket. Review the expanded configuration first.
cd falco-0.45.0/docker/docker-compose && docker-compose config - 3
Start the demo stack
Run this only on a Linux development or evaluation host, then open http://127.0.0.1:2802. The upstream README explicitly states that this Compose setup is not production-ready.
cd falco-0.45.0/docker/docker-compose && docker-compose up
Growth
Growth trends · Last 30 days
9,438 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 58
- Open PRs
- 19
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- cncf
- containers
- security
- falco
- ebpf
- kubernetes
- hacktoberfest
- cloud-native
- cncf-project
- runtime-security
- Stars
- 9,438
- Forks
- 1,084
- Watchers
- 131
- Open issues
- 28
- Contributors
- 233
- Owner type
- Organization
- Primary language
- C++
- License
- Apache-2.0
- Repository last updated
- Oct 3, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- containerd21,377 Stars
2 shared tag(s) · 1 shared category(s)
embed an industry-standard runtime daemon for image transfer, snapshots, container execution, and supervision beneath Kubernetes and container platforms
Go - cert-manager14,104 Stars
2 shared tag(s) · 1 shared category(s)
automate TLS certificate issuance and renewal inside Kubernetes while using ACME, Vault, and other issuers through shared resources
Go - Checkov9,054 Stars
2 shared tag(s) · 1 shared category(s)
statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment
Python - OWASP Dependency-Check7,715 Stars
2 shared tag(s) · 1 shared category(s)
match project dependencies to CPE and CVE data and detect known vulnerabilities from CLI, Maven, Gradle, and other build integrations
Java - CNI (Container Network Interface)6,126 Stars
2 shared tag(s) · 1 shared category(s)
CNI — the common contract between container runtimes and network plugins
Go - Opengrep3,136 Stars
2 shared tag(s) · 1 shared category(s)
scan 30+ languages for security issues with Semgrep-compatible rules
OCaml
Report incorrect information
Tell us if any listing information is incorrect or outdated.