Главная
Study mode:
on
1
Intro
2
What is Falco: Reminder
3
What is Falco: Now
4
Falco Architecture
5
libscap aka library for System Capture
6
libsinsp aka library for System INSPection
7
Falco: the Evolution
8
Plugins: Technical Details
9
Plugins: 2 Flavors
10
Source plugins: Sequence Diagram
11
Extractor plugins: Sequence Diagram
12
Plugins: Settings
13
Plugins: Technical Caveats
14
Plugin SDK Go: Why
15
Plugin SDK Go: Getting started
16
Plugins: The Registry
17
AWS Cloudtrail Plugin
18
JSON Plugin
19
Demo Time
20
WIP: Shared libs/modules for plugins
21
Falco with Real World: Pet Surveillance
22
Useful links
23
Contribute to Falco
Description:
Explore the evolution and extended capabilities of Falco, a cloud-native runtime security project, in this 42-minute CNCF conference talk. Dive into Falco's architecture, including libscap and libsinsp libraries, and learn about the new plugin system that allows for triggering alerts with any stream of events. Discover the technical details of source and extractor plugins, their implementation, and settings. Gain insights into the Plugin SDK Go, its benefits, and how to get started. Examine real-world applications, such as the AWS Cloudtrail and JSON plugins, through a live demonstration. Understand ongoing developments like shared libraries for plugins and see how Falco can be applied to pet surveillance. Conclude with useful links and information on how to contribute to the Falco project.

Extend Falco with Plugins - Trigger Alerts with Any Stream of Events

CNCF [Cloud Native Computing Foundation]
Add to list