-

Falco Open Source Adds AWS Cloud Security Monitoring

New Plug-in Capability Extends Open Source Threat Detection to Cloud

SAN FRANCISCO--(BUSINESS WIRE)--KubeCon + CloudNativeCon North America – Sysdig today announced the addition of cloud security monitoring functionality to the Falco open source software project. The new Amazon Web Services (AWS) CloudTrail plug-in provides real-time detection of unexpected behavior and configuration changes, intrusions, and data theft in AWS cloud services using Falco rules. The Falco community developed this extension with Sysdig based on a new plug-in framework that allows anyone to extend Falco to capture data from additional sources beyond Linux system calls and Kubernetes audit logs. As organizations manage critical data across multiple clouds, they need consistent threat detection across their distributed environments. Additional plug-ins will allow organizations to use a consistent threat detection language and close security gaps by using consistent policies for workloads and infrastructure. In addition, more than twenty new out-of-the-box policies supporting compliance frameworks were released.

Falco Community Blog: Falco Plugins Early Access

Falco, a cloud-native runtime security project, is the de facto detection engine for containers and Kubernetes with over thirty million downloads. Created by Sysdig and contributed to the CNCF, Falco is an Incubation-level hosted project. The new plug-in capability and framework have been contributed by the Falco community and Sysdig to the project over the last few months. As of today, the AWS CloudTrail plug-in is available for use in preview mode and contributors can build new plug-ins on the framework.

Real-time detection of cloud configuration risk and threats

Today, security teams are forced to export AWS CloudTrail logs into a data lake or security information and event management (SIEM) for processing, and then search for threats and changes to configurations that can indicate a risk. This approach adds delay in identifying risks, as well as cost and complexity.

Falco inspects cloud logs using a streaming approach, applying the rules to the logs in real time and immediately alerting on issues, without the need to make an additional copy of the data. This approach complements static cloud security posture management by continually checking for unexpected changes to configurations and permissions that can increase risk. In addition, it acts as a modern intrusion detection system (IDS), detecting threats based on unusual behavior that can indicate a threat.

Consistent tool for threat detection across containers and cloud

Cloud and security teams struggle with an ever-growing list of tools to master and manage. Falco provides a single tool for threat detection across container and cloud environments, reducing complexity by reducing the number of tools in the stack. Users can use the same rule language to create consistent policies for workloads and infrastructure, removing security gaps. Because there is a shortage of talent in both cybersecurity and DevOps, reducing the learning curve by using consistent tools for threat detection is critical.

Users can get started immediately using out-of-the-box rules contributed by the community that map to compliance frameworks and best practices. They can also create custom rules to meet their specific needs using standard YAML code.

The plug-in capability for Falco creates the foundation for contributions that will extend support to other cloud environments and operating systems. The AWS CloudTrail plug-in and additional out-of-the-box rules are immediately available to try in preview form on the Falco GitHub site. Falco users and contributors can access pre-release documentation now. The official release is planned in the upcoming months.

What the Community is Saying

“The Falco plug-in capability gives DevOps and security teams a single threat detection tool with a single rules language across container and cloud environments. This allows users to create consistent policies for workloads and infrastructure and close security gaps,” said Chris Aniszczyk, CTO of Cloud Native Computing Foundation. “The basis is now in place for rapid innovation by the community to extend Falco to additional cloud environments.”

“Now Falco can detect threats across containers and AWS cloud services using a streaming approach,'' said Loris Degioanni, Founder and Chief Technology Officer, Sysdig, “Users can immediately alert on indications of lateral movement without the cost and complexity of copying logs.”

Resources

About Sysdig:

Sysdig is driving the secure DevOps movement, empowering organizations to confidently secure containers, Kubernetes, and cloud. With Sysdig, teams secure the build, detect and respond to threats, continuously validate cloud configurations and compliance, and monitor performance. Sysdig is a SaaS platform, built on an open source stack that includes Falco and sysdig OSS, the open standards for runtime threat detection and response. Hundreds of companies rely on Sysdig for container and cloud security and visibility. Learn more at sysdig.com.

Sysdig


Release Summary
Sysdig contributes a new plug-in that extends Falco to AWS Cloud, along with 20 out-of-the-box compliance policies.
Release Versions

Social Media Profiles
More News From Sysdig

Amid Global Expansion and >330% Growth of Sysdig Sage™ AI, Sysdig Appoints Gary Olson CRO and Crendal Kear CBO

SAN FRANCISCO--(BUSINESS WIRE)--Sysdig, the leader in real-time cloud security, today announced the appointment of Gary Olson as Chief Revenue Officer (CRO) and Crendal Kear as Chief Business Officer (CBO) following a remarkable 337% growth in Sysdig Sage™ user adoption over the last eight months. Sysdig Sage, the industry’s first agentic artificial intelligence (AI) cloud security analyst, uses multi-step reasoning and contextual awareness to help security teams find, understand, and fix issue...

Sysdig Usage Report Reveals that Machine Identities Outnumber Humans 40,000 to 1, Presenting a Major Challenge to Enterprise Security

SAN FRANCISCO--(BUSINESS WIRE)--Sysdig, the leader in real-time cloud security, today released its “2025 Cloud-Native Security and Usage Report.” The company’s annual user analysis provides in-depth insights into real-world cloud security and usage trends, highlighting significant enterprise security progress while identifying key areas that demand urgent attention. The report reveals that organizations of every size and industry across North America; Europe, the Middle East, and Africa; and th...

Sysdig Unveils Stratoshark, Enabling Millions of Network Professionals to Bring Their Security Experience to the Cloud

BRUSSELS--(BUSINESS WIRE)--FOSDEM 2025 – Sysdig, the leader in real-time cloud security, today announced the release of Stratoshark, an open source tool that extends Wireshark’s granular network visibility into the cloud and empowers users with a standardized approach to cloud observability. For 27 years, Wireshark – with over 5 million daily users and more than 160 million downloads in the last decade alone – has helped users analyze network traffic and troubleshoot issues. As companies have t...
Back to Newsroom
  1. There was an issue with the authorization server. Please contact support if the issue persists.