# Runtime Security

Published articles for Runtime Security.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Splunk and Isovalent Runtime Security: Protecting the Platform Behind Splunk

DevFeed: [Splunk and Isovalent Runtime Security: Protecting the Platform Behind Splunk](<https://devfeed.tech/articles/splunk-and-isovalent-runtime-security-protecting-the-platform-behind-splunk-31338.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/splunk-and-isovalent-runtime-security-protecting-the-platform-behind-splunk/>)

Author: Dean Lewis

Published: 2026-07-09T06:02:44Z

Content type: article

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cilium](<https://devfeed.tech/tags/cilium.md>), [customer](<https://devfeed.tech/tags/customer.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [platform](<https://devfeed.tech/tags/platform.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [security](<https://devfeed.tech/tags/security.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

Splunk uses Isovalent Runtime Security, built on Tetragon, to protect its customer-facing platform.

### Source excerpt

Splunk uses Isovalent Runtime Security, built on Tetragon, to protect its customer facing platform.

## Taming the AI Double Threat with Isovalent Runtime Security

DevFeed: [Taming the AI Double Threat with Isovalent Runtime Security](<https://devfeed.tech/articles/taming-the-ai-double-threat-with-isovalent-runtime-security-31340.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/taming-the-ai-double-threat-with-isovalent-runtime-security/>)

Author: Paul Arah

Published: 2026-06-26T18:47:44Z

Content type: opinion

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [ai-assisted attacks](<https://devfeed.tech/topics/ai-assisted-attacks.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-attacks](<https://devfeed.tech/tags/ai-assisted-attacks.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [security](<https://devfeed.tech/tags/security.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

This blog post examines how AI-assisted attacks change assumptions about adversaries, the new attack surface introduced by AI workloads, and the infrastructure, identity, and runtime controls needed to address these risks with Isovalent Runtime Security.

### Source excerpt

This blog post explores how AI-assisted attacks are changing the assumptions we make about the adversary, the new attack surface AI workloads introduce, and the infrastructure, identity, and runtime controls they require, and finally, how teams can address this new threat landscape with Isovalent Runtime Security.

## Tetragon 1.7 adds fentry sensing, environment variable capture, parent-process visibility, and scoped policies

DevFeed: [Tetragon 1.7 adds fentry sensing, environment variable capture, parent-process visibility, and scoped policies](<https://devfeed.tech/articles/tetragon-1-7-precision-filtering-richer-context-and-better-performance-31341.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/tetragon-v1.7-release/>)

Author: Paul Arah

Published: 2026-06-09T14:01:46Z

Content type: release

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Processes](<https://devfeed.tech/topics/processes.md>), [Environment Variables](<https://devfeed.tech/topics/environment-variables.md>), [context](<https://devfeed.tech/topics/context.md>)

Tags: [cilium](<https://devfeed.tech/tags/cilium.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [policy](<https://devfeed.tech/tags/policy.md>), [process](<https://devfeed.tech/tags/process.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [sensor](<https://devfeed.tech/tags/sensor.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [visibility](<https://devfeed.tech/tags/visibility.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

Tetragon 1.7 introduces a new fentry sensor, environment variable capture, parent-process visibility, and granular policy scoping with hostSelector.

### Source excerpt

Tetragon 1.7 introduces a new fentry sensor, environment variables capturing, parent process visibility, granular policy scoping with hostSelector and more!

## Isovalent Private Networks and Cisco Nexus One: BGP EVPN Integration for the Enterprise Data Center

DevFeed: [Isovalent Private Networks and Cisco Nexus One: BGP EVPN Integration for the Enterprise Data Center](<https://devfeed.tech/articles/isovalent-private-networks-and-cisco-nexus-one-bgp-evpn-integration-for-the-enterprise-data-center-31333.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/isovalent-private-networks-and-cisco-nexus-one-bgp-evpn-integration-for-the-enterprise-data-center/>)

Author: Marcos Hernandez, Camillo Rossi

Published: 2026-06-04T16:42:52Z

Content type: release

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [virtualization](<https://devfeed.tech/topics/virtualization.md>), [networking](<https://devfeed.tech/topics/networking.md>), [BGP](<https://devfeed.tech/topics/bgp.md>), [Cisco](<https://devfeed.tech/topics/cisco.md>), [evpn](<https://devfeed.tech/topics/evpn.md>), [VXLAN](<https://devfeed.tech/topics/vxlan.md>), [datacenter](<https://devfeed.tech/topics/datacenter.md>)

Tags: [bgp](<https://devfeed.tech/tags/bgp.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [data-center](<https://devfeed.tech/tags/data-center.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [evpn](<https://devfeed.tech/tags/evpn.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [networking](<https://devfeed.tech/tags/networking.md>), [nexus-one](<https://devfeed.tech/tags/nexus-one.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>), [vxlan](<https://devfeed.tech/tags/vxlan.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

Isovalent announces the general availability of Isovalent Networking for Virtualization and highlights its BGP EVPN/VXLAN integration with Cisco NX-OS for enterprise data centers.

### Source excerpt

Today we're announcing the General Availability (GA) of Isovalent Networking for Virtualization alongside a deeper look at one of its core connectivity capabilities: BGP EVPN/VXLAN integration with Cisco NX-OS, part of the Cisco Nexus One strategic alignment.

## OpenAI Uses Isovalent for a Common Networking for AI Infrastructure

DevFeed: [OpenAI Uses Isovalent for a Common Networking for AI Infrastructure](<https://devfeed.tech/articles/openai-uses-isovalent-for-a-common-networking-for-ai-infrastructure-31334.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/openai-isovalent-networking-kubernetes-case-study/>)

Author: Dean Lewis

Published: 2026-06-03T10:42:00Z

Content type: article

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [networking](<https://devfeed.tech/topics/networking.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [networking](<https://devfeed.tech/tags/networking.md>), [openai](<https://devfeed.tech/tags/openai.md>), [policy](<https://devfeed.tech/tags/policy.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [troubleshooting](<https://devfeed.tech/tags/troubleshooting.md>), [uses](<https://devfeed.tech/tags/uses.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

The article reports that OpenAI uses Isovalent Networking for Kubernetes, built on Cilium, to provide consistent networking, policy, and troubleshooting across its AI infrastructure.

### Source excerpt

OpenAI uses Isovalent Networking for Kubernetes, built on Cilium, for consistent networking, policy, and troubleshooting across AI infrastructure.

## Isovalent Networking for Virtualization: Enterprise-Grade Network Segmentation and Multi-Tenancy for VMs in Kubernetes

DevFeed: [Isovalent Networking for Virtualization: Enterprise-Grade Network Segmentation and Multi-Tenancy for VMs in Kubernetes](<https://devfeed.tech/articles/isovalent-networking-for-virtualization-enterprise-grade-network-segmentation-and-multi-tenancy-for-vms-in-kubernetes-31332.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/isovalent-networking-for-virtualization/>)

Author: Marcos Hernandez

Published: 2026-06-02T12:59:28Z

Content type: release

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [Multi-tenancy](<https://devfeed.tech/topics/multi-tenancy.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [cilium](<https://devfeed.tech/tags/cilium.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [migrations](<https://devfeed.tech/tags/migrations.md>), [multi-tenancy](<https://devfeed.tech/tags/multi-tenancy.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [policy](<https://devfeed.tech/tags/policy.md>), [product](<https://devfeed.tech/tags/product.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

Isovalent announced the general availability of Isovalent Networking for Virtualization, a product that provides network segmentation, multi-tenancy, and policy enforcement for virtual machine workloads running in Kubernetes. It also streamlines migrations to KubeVirt.

### Source excerpt

We're formally announcing the General Availability of Isovalent Networking for Virtualization (INV), a purpose-built product that brings full network segmentation, multi-tenancy, and policy enforcement to virtual machine workloads running in Kubernetes, in addition to streamlining migrations to KubeVirt.

## Buzzing Beyond Clouds: The Illustrated Children's Guide to Cilium

DevFeed: [Buzzing Beyond Clouds: The Illustrated Children's Guide to Cilium](<https://devfeed.tech/articles/buzzing-beyond-clouds-the-illustrated-children-s-guide-to-cilium-31326.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/children-guide-cilium/>)

Author: Bill Mulligan, Katie Meinders

Published: 2026-05-19T10:23:39Z

Content type: release

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>)

Tags: [book](<https://devfeed.tech/tags/book.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

Buzzing Beyond Clouds is an illustrated children's guide to Cilium. The book is presented as a follow-up to an illustrated guide to eBPF and is intended for readers with varying levels of technical expertise.

### Source excerpt

Buzzing Beyond Clouds: The Illustrated Children's Guide to Cilium, and follow up to Buzzing Across Space: The Illustrated Children's Guide to eBPF, is now available. This second illustrated book brings the Cilium story to life in a way that can be digested by readers of all ages and levels of technical expertise.

## Falco Invites Community Feedback Through a 2026 Survey

DevFeed: [Falco Invites Community Feedback Through a 2026 Survey](<https://devfeed.tech/articles/blog-hey-falco-flock-let-s-soar-into-2026-32524.md>)

Original publisher: [Read original article](<https://falco.org/blog/soar-into-2026/>)

Published: 2026-02-25T00:00:00Z

Content type: opinion

Language: en

Sources: [Falco - Falco](<https://devfeed.tech/sources/falco-falco.md>), [Falco - The Falco blog](<https://devfeed.tech/sources/falco-the-falco-blog.md>)

Topics: [Falco](<https://devfeed.tech/topics/falco.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [community](<https://devfeed.tech/tags/community.md>), [falco](<https://devfeed.tech/tags/falco.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [survey](<https://devfeed.tech/tags/survey.md>)

### AI overview

Falco invites its community to complete a short survey about community connection, priorities, resources, tool integrations, and how people use Falco. The organization says it will share a report of the responses alongside KubeCon Europe 2026.

### Source excerpt

New year, new opportunities! As we spread our wings and glide into 2026, we want to make sure this community is one you're proud (and excited!) to be a part of. Falco has always been more than just a project: it's a flock of builders, defenders, contributors, question-askers, doc-writers, rule-tuners, and runtime security enthusiasts. And now we want to hear from you. We've put together a quick community survey (5 minutes or less!) to better understand: How connected you feel to the community What you love about being a part of it What could be better What you'd like to see us focus on this year What resources would make your life easier How you're using Falco and what tools you integrate it with Your feedback directly shapes our focus on what we build, improve, prioritize, and invest in this year - from documentation and content to events, integrations, and contributor experience. A report detailing the responses will be shared at the same time as KubeCon Europe 2026. Whether you're building, using, learning, or just keeping an eye on things, your voice matters. 👉 Take the survey here Thanks for being part of the flock. We couldn't do this without you and we're excited to build 2026 together!

## Blog: Detecting Supply Chain Attacks with Falco Actions

DevFeed: [Blog: Detecting Supply Chain Attacks with Falco Actions](<https://devfeed.tech/articles/blog-detecting-supply-chain-attacks-with-falco-actions-32479.md>)

Original publisher: [Read original article](<https://falco.org/blog/detecting-supplychain-attacks-with-falco-action/>)

Published: 2025-03-19T00:00:00Z

Content type: tutorial

Language: en

Sources: [Falco - Falco](<https://devfeed.tech/sources/falco-falco.md>), [Falco - The Falco blog](<https://devfeed.tech/sources/falco-the-falco-blog.md>)

Topics: [supply chain attacks](<https://devfeed.tech/topics/supply-chain-attacks.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>)

Tags: [cicd](<https://devfeed.tech/tags/cicd.md>), [falco](<https://devfeed.tech/tags/falco.md>), [github-action](<https://devfeed.tech/tags/github-action.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [supplychain](<https://devfeed.tech/tags/supplychain.md>)

### AI overview

This tutorial explains how to use Falco Actions in GitHub Actions workflows to detect suspicious behavior and software supply chain attacks in CI/CD pipelines. It covers runtime monitoring, custom rules, workflow setup, findings, and generated reports.

### Source excerpt

The recently discovered CVE for the GitHub action tj-actions/changed-files brought to light a topic that is really critical for companies: supply chain attacks. With that, we want to discuss and show a bit about how Falco can help your organization detect this kind of attack and other suspect behaviors inside your CI/CD pipeline. What is Falco? Falco is a cloud native security tool that provides runtime security across hosts, containers, Kubernetes, and cloud environments. It leverages custom rules on Linux kernel events and other data sources through plugins, enriching event data with contextual metadata to deliver real-time alerts. Falco enables the detection of abnormal behavior, potential security threats, and compliance violations. What is Falco Actions? Falco Actions enable you to run Falco in GitHub Actions to detect suspicious behavior in your CI/CD workflows. If you run it in a pull request, the action will create a comment with the findings. Thanks to ad-hoc Falco rules specific to this use case, these GitHub actions can monitor your GitHub runner and detect software supply chain attacks. Using Falco Actions To have Falco inside your pipeline, you need to add these two actions: falcosecurity/falco-actions/start falcosecurity/falco-actions/stop Below you can see an example: name: CI on: push: pull_request: jobs: build: runs-on: ubuntu-latest permissions: contents: read actions: read steps: - uses: actions/checkout@v4 - name: Start Falco uses: falcosecurity/falco-actions/start@main with: mode: live falco-version: '0.40.0' verbose: true - name: My Custom Step run: | echo "This is my custom step" - name: Stop Falco uses: falcosecurity/falco-actions/start@main with: mode: live verbose: true OBS: main is being used here only to simplify how it works, you should always pin your dependencies to a specific commit SHA. After the execution, you will be able to see the results at the github action summary. If you want a more detailed report, you can use the action fal

## Blog: Introducing the new Falco training course, by CNCF, Linux Foundation, and Sysdig

DevFeed: [Blog: Introducing the new Falco training course, by CNCF, Linux Foundation, and Sysdig](<https://devfeed.tech/articles/blog-introducing-the-new-falco-training-course-by-cncf-linux-foundation-and-sysdig-32522.md>)

Original publisher: [Read original article](<https://falco.org/blog/new-cncf-lf-training/>)

Published: 2023-11-06T00:00:00Z

Content type: release

Language: en

Sources: [Falco - Falco](<https://devfeed.tech/sources/falco-falco.md>), [Falco - The Falco blog](<https://devfeed.tech/sources/falco-the-falco-blog.md>)

Topics: [Falco](<https://devfeed.tech/topics/falco.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [linux foundation](<https://devfeed.tech/topics/linux-foundation.md>), [container-security](<https://devfeed.tech/topics/container-security.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [course](<https://devfeed.tech/tags/course.md>), [falco](<https://devfeed.tech/tags/falco.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

The article introduces Detecting Cloud Runtime Threats with Falco (LFS254), a 20-hour, self-paced training course created by CNCF, the Linux Foundation, and Sysdig. It covers runtime security, Falco's history, design, architecture, setup, operation, system call data, and other data sources.

### Source excerpt

Detecting Cloud Runtime Threats with Falco (LFS254) is the new Falco training course created by CNCF, Linux Foundation, and Sysdig. We're very excited about this new immersive course designed to enhance your expertise in securing cloud-native applications through hands-on learning. Detecting Cloud Runtime Threats with Falco (LFS254) is a 20-hour course focused on runtime security. It covers what is runtime security and how Falco is a powerful tool designed to detect anomalous activity in applications. From Falco's history and design principles to its architecture, to how it addresses cloud security challenges. This course is designed for IT professionals, security analysts, DevOps engineers, and anyone interested in cloud security. Why? In a rapidly evolving digital landscape with a surge in cloud adoption, the importance of comprehending and deploying robust security solutions, such as Falco, cannot be overstated. Regrettably, cloud-native technologies, particularly cloud-native security, are relatively novel, and there exists a gap in knowledge and expertise for addressing these emerging challenges. Our mission is to bridge this knowledge gap and empower individuals to tackle cloud and container security complexities effectively. Through accessible training, we aspire to contribute to narrowing the talent deficit in these pivotal domains. How? In this course, you'll embark on a journey of securing cloud-native environments. The course breaks down complex concepts, making them accessible and actionable. Its self-paced nature provides the flexibility to learn at your own rhythm, accommodating your personal and professional commitments. This structure allows you to digest intricate concepts and apply them bit by bit, ensuring a deeper and more lasting comprehension. Course Structure The course begins with an introduction to Falco, encompassing its history, design principles, and its broader role in cloud security. It then delves into the core components of Falco, exp

## Blog: Integrate Runtime Security into Your Environment with Falcosidekick

DevFeed: [Blog: Integrate Runtime Security into Your Environment with Falcosidekick](<https://devfeed.tech/articles/blog-integrate-runtime-security-into-your-environment-with-falcosidekick-32519.md>)

Original publisher: [Read original article](<https://falco.org/blog/integrate-runtime-security-with-falcosidekick/>)

Published: 2023-10-24T00:00:00Z

Content type: article

Language: en

Sources: [Falco - Falco](<https://devfeed.tech/sources/falco-falco.md>), [Falco - The Falco blog](<https://devfeed.tech/sources/falco-the-falco-blog.md>)

Topics: [Falco](<https://devfeed.tech/topics/falco.md>), [Security](<https://devfeed.tech/topics/security.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [AWS Lambda](<https://devfeed.tech/topics/aws-lambda.md>), [Cloud Functions](<https://devfeed.tech/topics/cloud-functions.md>), [Cloud Run](<https://devfeed.tech/topics/cloud-run.md>), [Kafka](<https://devfeed.tech/topics/kafka.md>), [RabbitMQ](<https://devfeed.tech/topics/rabbitmq.md>)

Tags: [aws-lambda](<https://devfeed.tech/tags/aws-lambda.md>), [cloud-functions](<https://devfeed.tech/tags/cloud-functions.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-run](<https://devfeed.tech/tags/cloud-run.md>), [falco](<https://devfeed.tech/tags/falco.md>), [falcosidekick](<https://devfeed.tech/tags/falcosidekick.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [kafka](<https://devfeed.tech/tags/kafka.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [notifications](<https://devfeed.tech/tags/notifications.md>), [rabbitmq](<https://devfeed.tech/tags/rabbitmq.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [security](<https://devfeed.tech/tags/security.md>), [tool](<https://devfeed.tech/tags/tool.md>)

### AI overview

This article explains how Falcosidekick extends Falco's limited default output options by forwarding runtime-security events to services such as Slack, PagerDuty, email, AWS Lambda, cloud functions, and message queues. It describes configurable notifications and automated responses for suspicious activity in cloud, container, and Kubernetes environments.

### Source excerpt

If you're looking to integrate runtime security into your existing environment, Falco is an obvious choice. Falco is a Cloud Native Computing Foundation backed open source project that provides real-time threat detection for cloud, container, and Kubernetes workloads. With over 80 million downloads Falco has been adopted by some of the largest companies in the world. However, what many Falco users discover early on is that Falco's default event output is rather limited. Out of the box, Falco can only send output to five different endpoints: syslog, stdout, stderr, and gRPC or HTTPS endpoints. While these outputs might be enough to get you started, most practitioners want to integrate Falco with the tooling they already use. This is where Falcosidekick comes in. Falcosidekick is a companion (i.e. a side-kick ;)) project for Falco that allows Falco events to be forwarded to 60 different services (with more being added all the time) allowing practitioners to monitor and react to Falco events with the tools they are already using. For example, if you'd like to receive immediate notifications of suspicious activity you can forward Falco events to chat programs such as Slack or Telegram, alerting platforms like PagerDuty or AlertManager, or, of course, email. In order to minimize noise, you can expressly set the level on which to notify, for example, warning-level events might be delivered via email, while critical or higher-level events are sent via chat or directed to your alerting platform. If you want to programmatically address certain events, Falcosidekick integrates with a bunch of different services including functions as a service platforms like AWS Lambda, GCP Cloud Run and Cloud Functions, or Knative. Alerts can also be sent to message queues like Amazon SNS, Apache Kafka, or RabbitMQ. These integrations offer almost endless possibilities for building out response systems for events. For instance, let's say you're running Falco on your Kubernetes cluster, and F