youtube image
From YouTube: Cloud Native Security with Falco — Tom Llewelyn 1.2.4

Description

What if we can detect abnormal behavior in the application, container runtime, cloud & cluster environment using the same method? In this talk, we’ll present Falco, a CNCF project for runtime security.

We will show how to use Falco to tap into Linux system calls, the Kubernetes audit logs, and cloud events to provide low level insight into application and platform behavior, and how to write security rules to detect abnormal behavior.

Falco is also featured in the CKS exam curriculum, so this session should be useful not only for securing your cloud native infrastructure, but also in passing the CKS!