Shift-Left Is Not Enough
Vulnerability scanning catches known CVEs before deployment. Policy enforcement prevents misconfigurations at admission. But what about threats that emerge at runtime — a compromised container downloading cryptomining software, an attacker exploiting a zero-day, or a service account being used for lateral movement? Runtime security is the third leg of the Kubernetes security tripod, and it's explicitly required by DORA and NIS2.
Falco, the CNCF Graduated runtime security project, monitors system calls in real-time to detect anomalous and malicious behaviour in containers and Kubernetes.
What Falco Detects
Runtime Threats
- Shell spawning: A shell (bash, sh) opened inside a container that shouldn't have interactive access
- Unexpected network connections: Container connecting to an external IP/domain not in its normal behaviour
- File system modifications: Write to sensitive paths (/etc, /usr/bin) in containers with read-only root filesystems
- Privilege escalation: Process attempting to change user to root or modify capabilities
- Cryptomining: Detection of mining software execution patterns (stratum protocol, known binary names)
- Container escape: Attempts to access host filesystem, cgroups, or namespaces from within a container
- Sensitive file access: Reading /etc/shadow, /etc/passwd, or credential files
- Kubernetes API abuse: Unexpected calls to the K8s API server (service account token misuse)
How It Works
- eBPF driver: Attaches to the Linux kernel to monitor system calls in real-time — zero application changes needed
- Rule engine: YAML-based rules define what constitutes suspicious behaviour
- Kubernetes context: Falco enriches events with pod name, namespace, labels, container image — not just raw syscalls
- Alert output: Send alerts to stdout, syslog, HTTP webhook, Kafka, NATS, gRPC — integrate with any SIEM
Compliance Mapping
- DORA Art. 10 (Detection): Falco provides continuous runtime monitoring of ICT systems — detecting anomalous behaviour that static scanning misses
- DORA Art. 17-23 (Incident Management): Falco alerts feed directly into incident detection and classification workflows
- NIS2 Art. 21(2)(b) (Incident Handling): Runtime detection is a prerequisite for incident handling — you can't handle what you can't detect
- NIS2 Art. 21(2)(a) (Risk Management): Runtime security monitoring is a key risk management measure
- EU AI Act Art. 15 (Cybersecurity): Runtime monitoring of AI inference systems detects exploitation attempts
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Falco vs Commercial CWPP
| Feature | Falco (OSS) | Sysdig Secure | Aqua Security |
|---|---|---|---|
| Cost | Free (open source) | Enterprise pricing | Enterprise pricing |
| Runtime detection | Syscall rules (powerful) | Falco-based + ML | Behavioral profiling |
| Image scanning | No (use Trivy) | Included | Included |
| Compliance reports | Custom (build yourself) | Pre-built (CIS, NIST, PCI) | Pre-built |
Deployment Guide
- Deploy Falco via Helm with the eBPF driver (preferred over kernel module)
- Start with default rules — Falco ships with comprehensive rules for common threats
- Tune for your environment — Expect false positives initially. Whitelist known-good behaviours per namespace/workload.
- Route alerts to SIEM — Falcosidekick provides 60+ output integrations (Slack, PagerDuty, Elasticsearch, Kafka, etc.)
- Build incident response playbooks — Each Falco rule category should map to a specific response procedure
Federated Learning and Privacy-preserving RAGs
Implement secure AI models using federated learning techniques.
Start on Pluralsight →
Luca Berton
