7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Falco

Open source

Cloud native runtime security tool that monitors Linux kernel events and alerts on abnormal behavior and threats in real time.

falco.org
Falco homepage screenshot
GitHub stars
9.4k
Last commit
2 days ago
Repository age
10 years
Version
0.45.0
Licence
Apache-2.0
Self-hosted
Yes

About Falco

Falco is a cloud native runtime security tool for Linux. It detects and alerts on abnormal behavior and potential security threats in real time. At its core it is a kernel monitoring and detection agent that watches events such as system calls and evaluates them against custom rules.

Falco can enrich events with metadata from the container runtime and from Kubernetes, and the collected events can be analyzed off-host in SIEM or data lake systems. The project is split across repositories in the falcosecurity organization: the main repo holds the Falco binary, while others hold the core libraries and kernel drivers, the official ruleset, and plugins that extend detection beyond syscalls and container events.

Falco was originally created by Sysdig and is a graduated project of the Cloud Native Computing Foundation, used in production by various organizations. It is written in C++ and released under the Apache-2.0 license, with a change log and detailed documentation on falco.org. Topics in the repository mention eBPF-based collection.

Key features

  • Kernel-level syscall monitoring
  • Custom detection rules
  • Container and Kubernetes metadata enrichment
  • Official ruleset for common threats
  • Plugins for additional event sources
  • Export to SIEM or data lake systems

Good fit for

  • →Detecting suspicious container behavior
  • →Runtime threat alerts for Kubernetes clusters
Built with
C++
Kubernetes
Tags
runtime-security
kubernetes
containers
ebpf
cncf
threat-detection
linux
cloud-native

Falco: questions and answers

What is Falco used for?
Falco is a cloud native runtime security tool that monitors Linux kernel events and alerts on abnormal behavior and threats in real time. It is a good fit for detecting suspicious container behavior and runtime threat alerts for Kubernetes clusters.
Is Falco open source?
Yes. Falco is open source under the Apache-2.0 licence. Its source code is on GitHub at falcosecurity/falco and is written mainly in C++.
Is Falco free?
Yes. Falco is open source, so the software itself is free to use.
Can I self-host Falco?
Yes. Falco can be self-hosted on your own server or infrastructure; there is no official hosted version.
What is Falco an alternative to?
Falco is an open-source alternative to Wiz, CrowdStrike, Palo Alto Networks and SentinelOne. Other open-source alternatives to Wiz include Kubescape, Trivy and Grype.
Is Falco actively maintained?
Yes. The most recent commit to Falco was on 30 September 2026, and the latest release is 0.45.0, published on 21 September 2026. The project has 9.4k stars on GitHub.

Open-source alternatives to Falco

See all

SaaS alternatives to Falco

See all