All Tools
F
MonitoringFreeOpen Source
FALCO
Runtime security detection for Kubernetes and containers
Apache-2.0
ABOUT
Image scans miss attacks that start after a pod is running. Falco watches syscalls and Kubernetes audit events against rules so a GPU node running training or inference alerts on unexpected shells, miners, and reads of secrets or model files.
INTEGRATION GUIDE
1. Alert when an inference container spawns an unexpected shell
2. Detect crypto miners on GPU nodes that should only run training jobs
3. Watch Kubernetes audit events for unexpected Secret or ConfigMap access
4. Stream Falco alerts into an ML ops incident channel for runtime threats
TAGS
securitykubernetesruntimecontainersobservabilitycncfopen-source