Tools/Falco
Falco
CNCF open-source runtime security tool — detects anomalous/malicious behavior in containers, Kubernetes, and hosts by tailing syscalls and Kubernetes audit events against a rules engine. The audit-log analogue to AWS_CloudTrail when the "account" is a cluster rather than an AWS account; narrower and more runtime-focused than Wazuh (full SIEM/XDR), and commonly deployed alongside it or Amazon_GuardDuty for Kubernetes-specific coverage GuardDuty doesn't fully reach.