Skip to content

Entry

Falco

Appears in 5 awesome lists

Behavioral activity monitor designed to detect anomalous activity in containerized applications, hosts, and network packet flows by auditing the Linux kernel and enriched by runtime data such as Kubernetes metrics.

Open falco.org

Found in these lists

Awesome Cybersecurity Blue Team

Section: Cloud platform security · Behavioral activity monitor designed to detect anomalous activity in containerized applications, hosts, and network packet flows by auditing the Linux kernel and enriched by runtime data such as Kubernetes metrics.

StaleScore 53

Awesome Cybersecurity Blue Team - CN

Section: 云平台安全 · 行为活动监视器,旨在通过审核Linux内核和运行时数据(例如Kubernetes指标)进行拓展和丰富,以检测容器化的应用程序,以及主机和网络数据包流中的异常活动

StaleScore 47

Awesome eBPF

Section: Security · A cloud-native runtime security project used as a Kubernetes threat detection engine.

FreshScore 87

Awesome Proxmox VE

Section: Security Tools & Best Practices

FreshScore 82

Awesome Security

Section: Monitoring / Logging · The cloud-native runtime security project and de facto Kubernetes threat detection engine now part of the CNCF.

SlowScore 70

gVisor

gVisor is a user-space kernel, written in Go, that implements a substantial portion of the Linux system surface. It includes an Open Container Initiative (OCI) runtime called runsc that provides an isolation boundary between the application and the host kernel. The runsc runtime integrates with…

In 7 listsDetails

Tracee

A runtime security and forensics tool for Linux which uses eBPF technology to trace the system and applications at runtime, and analyze collected events to detect suspicious behavioral patterns.

In 5 listsDetails

Kata Containers

Secure container runtime with lightweight virtual machines that feel and perform like containers, but provide stronger workload isolation using hardware virtualization technology as a second layer of defense.

In 5 listsDetails

Istio

is an open platform to connect, manage, and secure microservices. Istio's control plane provides an abstraction layer over the underlying cluster management platform, such as Kubernetes and Mesos.

In 5 listsDetails

Tetragon

Kubernetes-aware, eBPF-based security observability and runtime enforcement.

In 4 listsDetails

Checkov

对于Terraform(在DevOps实践中,代码即基础设施概念)的静态分析器。可以帮助检测CIS策略违规行为,并防止云安全策略配置错误; 补充:Terraform是一种安全有效地构建、更改和版本控制基础设施的工具(基础架构自动化的编排工具)[1]; 补充:CIS基准是安全配置系统的配置基线和最佳做法[2]

In 3 lists

Scout Suite

Open source multi-cloud security-auditing tool, which enables security posture assessment of cloud environments.

In 4 lists

Sysmon for Linux

A security monitoring tool. It depends on SysinternalsEBPF.

In 3 lists