Ross ROSS = Recommend OSS · open-source software intelligence for agents

falcosecurity/falco

Cloud Native Runtime Security observed · 2026-08-28

github.com/falcosecurity/falco · homepage · C++ · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 95
  • Release rhythm 88
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 15
  • age_days: 3879
  • days_rel: 83
  • days_push: 30
  • n_releases_24m: 16

Full methodology

Adoption not part of the score

9305 stars · 1065 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Falco is a CNCF-graduated cloud native runtime security tool for Linux that monitors kernel events (syscalls) via eBPF or kernel modules and detects abnormal behavior using customizable rules. It enriches events with container and Kubernetes metadata and delivers real-time alerts that can be forwarded to SIEM and data lake systems.

Use cases

  • detect runtime security threats in containers and kubernetes
  • monitor linux syscalls for suspicious behavior
  • alert on privilege escalation and shell spawning in production
  • detect kubernetes cluster intrusions in real time
  • maintain pci dss and mitre att&ck compliance monitoring
  • forward security alerts to siem or data lake
  • monitor cloud audit logs like aws cloudtrail and okta

When to choose

  • you run linux hosts, containers, or kubernetes and need real-time runtime threat detection
  • you want a lightweight, low-overhead eBPF-based monitoring agent with a single policy language
  • you need out-of-the-box rules plus extensibility via plugins and 50+ alert integrations

When to avoid

  • you need endpoint protection on non-Linux systems like Windows or macOS
  • you want a full managed SIEM or antivirus product rather than a detection agent
  • you cannot run privileged workloads or eBPF/kernel modules on your hosts

Facets

application · maturity stable

monitoring alerting security logging security cloud-computing monitoring self-hosted cloud runtime-security ebpf threat-detection syscall-monitoring cncf siem-integration kubernetes-security intrusion-detection containers devops linux kubernetes docker

10 sources

Member repositories

RepositoryRoleHealth v2
falcosecurity/falcomain94

For agents

markdown · JSON · MCP: product_card(name="falcosecurity/falco")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem