Falco can consume events from different sources, and apply rules to these events to detect abnormal behavior. Currently Falco supports the following event sources:
- System Calls (syscall) via the drivers
- Kubernetes Audit Events (k8s_audit)
Table of contents