Falco Rules Logo

Falco Rules

0
Free
Visit Website

This repository contains officially managed Falco Rules by The Falco Project, pre-defined detections for security threats, abnormal behaviors, and compliance-related monitoring. Users can modify community-contributed rules or create custom ones, focusing on syscalls and container events. Stay updated with the Rules Overview Document and release notes for evolving threats and systems.

FEATURES

ALTERNATIVES

A method for profiling SSL/TLS Clients with easy-to-produce client fingerprints.

Smart traffic sniffing tool for penetration testers

Prisma SASE is a cloud-delivered service integrating network security, SD-WAN, and user experience management for comprehensive protection and optimization of hybrid work environments.

A honeypot that logs NTP packets into a Redis database to detect DDoS attempts.

Python module for fast packet parsing with TCP/IP protocol definitions.

A suite for man in the middle attacks, featuring sniffing of live connections, content filtering, and protocol dissection.

A module for loading Bro logs as tables in Osquery

A free DNS recursive service that blocks malicious host names and protects user privacy.

PINNED