# falcosecurity/falco

Cloud Native Runtime Security

Repository: https://github.com/falcosecurity/falco
Canonical: https://ross.abutalabs.com/products/falco
Homepage: https://falco.org
Language: C++
License: Apache-2.0
License Family: permissive
Topics: cncf, containers, security, falco, ebpf, kubernetes, hacktoberfest, cloud-native, cncf-project, runtime-security
Last push: 2026-08-03T07:39:35+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 95, release rhythm 88, longevity 100
- inputs: {"age_days": 3879, "days_push": 30, "days_rel": 83, "gap_med": 15, "n_releases_24m": 16}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 9305, forks 1065 (observed 2026-08-28T04:10:30.467499+00:00)

## What it is
Falco is a CNCF-graduated cloud native runtime security tool for Linux that monitors kernel events (syscalls) via eBPF or kernel modules and detects abnormal behavior using customizable rules. It enriches events with container and Kubernetes metadata and delivers real-time alerts that can be forwarded to SIEM and data lake systems.

## Use cases
- detect runtime security threats in containers and kubernetes
- monitor linux syscalls for suspicious behavior
- alert on privilege escalation and shell spawning in production
- detect kubernetes cluster intrusions in real time
- maintain pci dss and mitre att&ck compliance monitoring
- forward security alerts to siem or data lake
- monitor cloud audit logs like aws cloudtrail and okta

## When to choose
- you run linux hosts, containers, or kubernetes and need real-time runtime threat detection
- you want a lightweight, low-overhead eBPF-based monitoring agent with a single policy language
- you need out-of-the-box rules plus extensibility via plugins and 50+ alert integrations

## When to avoid
- you need endpoint protection on non-Linux systems like Windows or macOS
- you want a full managed SIEM or antivirus product rather than a detection agent
- you cannot run privileged workloads or eBPF/kernel modules on your hosts

## Facets
- artifact type: application
- maturity: stable
- function: monitoring, alerting, security, logging
- domain: security, cloud-computing, monitoring
- platform: self-hosted, cloud
- tags: runtime-security, ebpf, threat-detection, syscall-monitoring, cncf, siem-integration, kubernetes-security, intrusion-detection, containers, devops, linux, kubernetes, docker

## Member repositories
- falcosecurity/falco (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:30.467499+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:22:31.292949+00:00, confidence not recorded.
  - readme: https://github.com/falcosecurity/falco (fetched 2026-08-28T04:10:30.467499+00:00, sha aa2dd3290c6e)
  - homepage: https://falco.org (fetched 2026-08-29T08:22:41.817950+00:00, sha c1326ba2b619)
  - site_page: https://falco.org/about (fetched 2026-08-29T08:22:41.826971+00:00, sha 4fe5d21fcdfe)
  - site_page: https://falco.org/about/why-falco (fetched 2026-08-29T08:22:41.828841+00:00, sha ad6a04ec20ca)
  - site_page: https://falco.org/about/use-cases (fetched 2026-08-29T08:22:41.830700+00:00, sha 8cc1b60a1016)
  - site_page: https://falco.org/about/case-studies (fetched 2026-08-29T08:22:41.832369+00:00, sha 768e3e22c506)
  - site_page: https://falco.org/about/ecosystem (fetched 2026-08-29T08:22:41.833817+00:00, sha 7c198a7a4b3b)
  - site_page: https://falco.org/about/faq (fetched 2026-08-29T08:22:41.836836+00:00, sha a0cc3322d127)
  - site_page: https://falco.org/docs (fetched 2026-08-29T08:22:41.839742+00:00, sha 4928517bcfba)
  - site_page: https://falco.org/community (fetched 2026-08-29T08:22:41.841668+00:00, sha 949da973beff)
- Data as of 2026-08-30T08:39:29.467469+00:00.
