Threat-Detection Tool Falco Now Supports Multiple Event Sources, Syscall Selection, and More

The latest release of Falco adds the ability to handle multiple simultaneous event sources within the same instance, support for selecting which syscalls to capture, a new Kernel Crawler to collect the most recent supported kernel versions, and more. Up until version 0.33.0, the only way for Falco to consume events from multiple event sources was to deploy multiple instances of Falco, one for each event source.

Read full article on InfoQ

 


Date:

Categorie(s):