Falco Plugins - Introduction to Falco Plugins

Oct 18, 2022

The first video in the free "Falco Plugins" training course hosted at the Sysdig learning portal:

We will introduce how Falco can be extended to be used for data sources beyond syscalls, opening up use cases covering detections on cloud-native platforms using any JSON compatible logs from cloud vendors, or sources such as AWS Cloudtrail.

Below are some of the topics you can expect to find as part of Falco Plugins:

00:00 Introduction

00:31 Falco & cloud workloads

01:09 Architecture

01:43 Plugin sources

02:23 Falco rules for plugins

03:14 Configuration

03:50 Types of plugins

04:22 Conclusion