Runtime Security

Kubernetes monitoring, Falco, Gatekeeper, and runtime defense

Detecting Attacks with Linux auditd

Tracing syscalls, watching files, and catching command injection using the Linux kernel audit framework with a vulnerable ICMP tool as the attack surface

Read tutorial →

Runtime K8s Monitoring with Gatekeeper and Falco

Kubernetes runtime security using OPA Gatekeeper admission policies and Falco runtime detection

Read tutorial →

Memfd Syscall In-Memory Execution

Fileless in-memory attacks in Kubernetes using memfd_create syscall with Docker and Perl

Read tutorial →