Skip to main content
← All posts·
Platform Engineering

Falco for Regulated Enterprises: Kubernetes Runtime Security & Threat Detection

Falco runtime security guide for regulated enterprises. Real-time threat detection in Kubernetes using eBPF syscall monitoring. Covers cryptomining detection, container escape prevention, compliance-ready alerting, and DORA/NIS2 incident detection requirements.

Luca Berton11 min read

Shift-Left Is Not Enough

Vulnerability scanning catches known CVEs before deployment. Policy enforcement prevents misconfigurations at admission. But what about threats that emerge at runtime — a compromised container downloading cryptomining software, an attacker exploiting a zero-day, or a service account being used for lateral movement? Runtime security is the third leg of the Kubernetes security tripod, and it's explicitly required by DORA and NIS2.

Falco, the CNCF Graduated runtime security project, monitors system calls in real-time to detect anomalous and malicious behaviour in containers and Kubernetes.

What Falco Detects

Runtime Threats

  • Shell spawning: A shell (bash, sh) opened inside a container that shouldn't have interactive access
  • Unexpected network connections: Container connecting to an external IP/domain not in its normal behaviour
  • File system modifications: Write to sensitive paths (/etc, /usr/bin) in containers with read-only root filesystems
  • Privilege escalation: Process attempting to change user to root or modify capabilities
  • Cryptomining: Detection of mining software execution patterns (stratum protocol, known binary names)
  • Container escape: Attempts to access host filesystem, cgroups, or namespaces from within a container
  • Sensitive file access: Reading /etc/shadow, /etc/passwd, or credential files
  • Kubernetes API abuse: Unexpected calls to the K8s API server (service account token misuse)

How It Works

  • eBPF driver: Attaches to the Linux kernel to monitor system calls in real-time — zero application changes needed
  • Rule engine: YAML-based rules define what constitutes suspicious behaviour
  • Kubernetes context: Falco enriches events with pod name, namespace, labels, container image — not just raw syscalls
  • Alert output: Send alerts to stdout, syslog, HTTP webhook, Kafka, NATS, gRPC — integrate with any SIEM

Compliance Mapping

  • DORA Art. 10 (Detection): Falco provides continuous runtime monitoring of ICT systems — detecting anomalous behaviour that static scanning misses
  • DORA Art. 17-23 (Incident Management): Falco alerts feed directly into incident detection and classification workflows
  • NIS2 Art. 21(2)(b) (Incident Handling): Runtime detection is a prerequisite for incident handling — you can't handle what you can't detect
  • NIS2 Art. 21(2)(a) (Risk Management): Runtime security monitoring is a key risk management measure
  • EU AI Act Art. 15 (Cybersecurity): Runtime monitoring of AI inference systems detects exploitation attempts
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare →

Falco vs Commercial CWPP

FeatureFalco (OSS)Sysdig SecureAqua Security
CostFree (open source)Enterprise pricingEnterprise pricing
Runtime detectionSyscall rules (powerful)Falco-based + MLBehavioral profiling
Image scanningNo (use Trivy)IncludedIncluded
Compliance reportsCustom (build yourself)Pre-built (CIS, NIST, PCI)Pre-built

Deployment Guide

  1. Deploy Falco via Helm with the eBPF driver (preferred over kernel module)
  2. Start with default rules — Falco ships with comprehensive rules for common threats
  3. Tune for your environment — Expect false positives initially. Whitelist known-good behaviours per namespace/workload.
  4. Route alerts to SIEM — Falcosidekick provides 60+ output integrations (Slack, PagerDuty, Elasticsearch, Kafka, etc.)
  5. Build incident response playbooks — Each Falco rule category should map to a specific response procedure
🎓 Course

Federated Learning and Privacy-preserving RAGs

Implement secure AI models using federated learning techniques.

Start on Pluralsight →
Falco
runtime security
Kubernetes
threat detection
eBPF
compliance
regulated enterprises

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →