Runtime detection for your containers.

Multi-engine runtime detection: Falco (behavioral container/Kubernetes/Linux, ATT&CK Containers-mapped) + Tetragon (eBPF, detects AND blocks at kernel level), plus cloud audit (Kubernetes audit, AWS CloudTrail, Okta, GCP). Every rule validated on its own engine; forged maison rules + the permissively-licensed open-source ecosystem.

430+
rules
ATT&CK
index + bundles shipped
2 moteurs
each engine-validated
Ed25519
signed, updated

What we added recently

A living feed: here is the coverage added to it, dated.

  • +83 règles
  • +78 règles

The runtime abuses that matter in containers.

Cryptomining

Mining binaries launched inside a container (T1496).

Container escape

nsenter/unshare/mount and host-escape tooling (T1611).

Credential access

Reads of K8s tokens, /etc/shadow, SSH keys (T1552).

Persistence

cron/systemd/ld.so.preload writes, kernel modules, setuid (T1543/T1547).

Execution

Interactive shells, netcat/reverse-shell, runtime package managers (T1059/T1195).

Discovery

Network recon tools and container admin commands (T1046/T1609).

Cloud audit

Kubernetes audit, AWS CloudTrail, Okta, GCP, GitHub, via Falco plugins (each ruleset needs its plugin).

Your SIEM rules, ported to Falco

Cloud detections from the Sigma standard (AWS CloudTrail, GCP audit) translated into Falco rules: both engines read the same JSON record, so the detection logic is preserved, and every converted rule is validated on the real Falco engine before delivery.

Runtime: forged maison rules (ATT&CK Containers) + the open-source Falco rules ecosystem (Apache 2.0), validated on the real engine. Cloud: official Falco plugin rulesets (k8saudit, cloudtrail, okta, gcpaudit, github), loaded with their plugin, + Sigma cloud detections translated to Falco (derivative works under DRL-1.1). The pack ships each rule’s licence in its index, you know exactly what you are loading.

Validated on the real engine, not just YAML.

01
Validated on each engine

Falco rules pass `falco --validate` on the real engine; Tetragon policies are validated against the official CRD schema, the very one the Kubernetes API enforces on admission. Nothing breaks on load.

02
Original maison content

Rules forged by us, not a mere mirror of a public repo.

03
ATT&CK index + bundles shipped

The pack ships a coverage index (by tactic, technique, engine, platform) and ready-to-load bundles: container escape, credential access, Kubernetes runtime, cloud audit. You don’t get a bag of YAML, you get a map of what you cover, and what you don’t cover is counted too.

04
Clean license

the open-source Falco upstream under Apache 2.0, redistributable under its own license (attribution kept); our in-house Falco rules and the curated pack stay proprietary (EULA, subscriber use).

05
Ed25519-signed

The feed is signed; you verify its integrity before loading.

06
One key, kept current

A single subscription, updated as research and new techniques emerge.

Which Falco version is it compatible with?

The rules target a modern engine version (required_engine_version) and are validated on the latest official Falco image. Load them with `falco -r <file>.yaml` or via `rules_files` in falco.yaml.

How is it different from Falco Feeds (Sysdig)?

Same open-source Falco engine. Our edge: forged, validated maison rules mapped to ATT&CK Containers, aggregated with the Apache ecosystem, delivered signed under one key, at an SMB price. The Apache upstream stays redistributable under its own license; our in-house rules and the compilation are proprietary (EULA).

What sources and licenses?

Our in-house Falco rules (proprietary), plus the open-source Falco rules ecosystem (Apache 2.0). The Apache upstream is redistributable under its own license, attribution kept in the pack; our in-house rules and the curated compilation stay proprietary (EULA, use by the subscribing organization), the pack itself is not resold or redistributed as-is.

Ready to watch your containers?

Annual subscription. Instant key. Cancel anytime.

€349 / month, billed annually €4,188 excl. tax
Try before you buy: free demo pack

A sample of our in-house rules across every engine we run (Sigma, YARA, osquery, Velociraptor, Falco, network, policy), each detection with its investigation playbook in the CACAO 2.0 standard, importable into your SOAR. The Sigma rules come already converted for 6 SIEMs: Splunk, Sentinel, Elastic, QRadar, CrowdStrike and Panther. A NIS2 compliance-coverage sample is included. Generated without AI.

Download the demo pack .zip

What this pack does not cover

What we do not cover, we tell you

No one detects 100%, and a feed that claims otherwise burns out your analyst. Anything that does not compile on the real engine, or lights up on a benign corpus, never reaches the pack. What a rule cannot see, we show as a gap rather than paper over it. And by default the agent observes and proposes, acting only after human validation (human-in-the-loop). You buy signal, not volume.

Detection that holds up in front of the auditor

The question is no longer only “can I detect?” but “can I prove it?”. Every subscription ships with the compliance layer, at no extra cost.

Design coverage, not a certification nor a real-time measurement: it evidences that the catalogue addresses the requirement, your CISO validates compliance.

Detection guides

The method behind the pack, on our blog.