falcosecurity/falco
Cloud Native Runtime Security observed · 2026-08-28
Health v2 · maintenance only
94/100
- Activity 95
- Release rhythm 88
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 15
- age_days: 3879
- days_rel: 83
- days_push: 30
- n_releases_24m: 16
Adoption not part of the score
9305 stars · 1065 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Falco is a CNCF-graduated cloud native runtime security tool for Linux that monitors kernel events (syscalls) via eBPF or kernel modules and detects abnormal behavior using customizable rules. It enriches events with container and Kubernetes metadata and delivers real-time alerts that can be forwarded to SIEM and data lake systems.
Use cases
- detect runtime security threats in containers and kubernetes
- monitor linux syscalls for suspicious behavior
- alert on privilege escalation and shell spawning in production
- detect kubernetes cluster intrusions in real time
- maintain pci dss and mitre att&ck compliance monitoring
- forward security alerts to siem or data lake
- monitor cloud audit logs like aws cloudtrail and okta
When to choose
- you run linux hosts, containers, or kubernetes and need real-time runtime threat detection
- you want a lightweight, low-overhead eBPF-based monitoring agent with a single policy language
- you need out-of-the-box rules plus extensibility via plugins and 50+ alert integrations
When to avoid
- you need endpoint protection on non-Linux systems like Windows or macOS
- you want a full managed SIEM or antivirus product rather than a detection agent
- you cannot run privileged workloads or eBPF/kernel modules on your hosts
Facets
application · maturity stable
monitoring alerting security logging security cloud-computing monitoring self-hosted cloud runtime-security ebpf threat-detection syscall-monitoring cncf siem-integration kubernetes-security intrusion-detection containers devops linux kubernetes docker
10 sources
- readme: https://github.com/falcosecurity/falco · fetched 2026-08-28 · aa2dd3290c6e
- homepage: https://falco.org · fetched 2026-08-29 · c1326ba2b619
- site_page: https://falco.org/about · fetched 2026-08-29 · 4fe5d21fcdfe
- site_page: https://falco.org/about/why-falco · fetched 2026-08-29 · ad6a04ec20ca
- site_page: https://falco.org/about/use-cases · fetched 2026-08-29 · 8cc1b60a1016
- site_page: https://falco.org/about/case-studies · fetched 2026-08-29 · 768e3e22c506
- site_page: https://falco.org/about/ecosystem · fetched 2026-08-29 · 7c198a7a4b3b
- site_page: https://falco.org/about/faq · fetched 2026-08-29 · a0cc3322d127
- site_page: https://falco.org/docs · fetched 2026-08-29 · 4928517bcfba
- site_page: https://falco.org/community · fetched 2026-08-29 · 949da973beff
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| falcosecurity/falco | main | 94 |
For agents
markdown · JSON · MCP: product_card(name="falcosecurity/falco")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem