---
title: Detecting Threats and Securing the Kubernetes Environment with Falco
description: We are always looking for best practices while working with the Kubernetes cluster to secure our system. Sometimes, it can be hard to keep our system secure despite all these precautions. This blog post will explore using open-source Falco to detect unexpected behaviour and alerts on threats at runtime.
image: https://www.bionconsulting.com/hubfs/Bion-falco-blog.jpg
---

[![bion-logo-122x40](https://www.bionconsulting.com/hubfs/bion-logo-122x40.png)](https://www.bionconsulting.com)

- [Home](https://www.bionconsulting.com)
- Services 
    - DevOps 
          - [DevOps as a Service](https://www.bionconsulting.com/devops-as-a-service)
          - [DevOps Services](https://www.bionconsulting.com/services/devops/devops-services)
          - [AWS DevOps Consulting](https://www.bionconsulting.com/services/devops/aws-devops-consulting)
    - DevSecOps 
          - [DevSecOps Consulting](https://www.bionconsulting.com/services/devsecops)
          - [DevSecOps Assessment](https://www.bionconsulting.com/services/devsecops-assessment)
          - [Software Supply Chain Security](https://www.bionconsulting.com/partnerships/anchore)
    - Kubernetes 
          - [Kubernetes Consulting](https://www.bionconsulting.com/services/kubernetes/kubernetes-consulting-services)
          - [Kubernetes Security](https://www.bionconsulting.com/services/kubernetes/security)
          - [Kubernetes Managed Services](https://www.bionconsulting.com/services/kubernetes/managed-services)
          - [Kubernetes Migration Services](https://www.bionconsulting.com/services/kubernetes/migration-services)
          - [Kubernetes Training](https://www.bionconsulting.com/services/kubernetes/training)
    - AWS 
          - [AWS Security Assessment](https://www.bionconsulting.com/services/aws/security-assessment)
          - [AWS Cloud Security](https://www.bionconsulting.com/services/aws/cloud-security)
          - [AWS Architecture Design](https://www.bionconsulting.com/services/aws/architecture-design)
          - [AWS Managed Services](https://www.bionconsulting.com/services/aws/managed-services)
          - [AWS Migration Services](https://www.bionconsulting.com/services/aws/migration-services)
          - [AWS Cost Optimisation](https://www.bionconsulting.com/services/aws/aws-cost-optimisation)
          - [AWS CPPO](https://www.bionconsulting.com/services/aws/aws-cppo)
    - AI Infrastructure Services 
          - [AI Platform Architecture](https://www.bionconsulting.com/ai-platform-architecture)
          - [Generative AI & LLM Deployment on AWS](https://www.bionconsulting.com/generative-ai-llm-deployment-aws)
          - [AI Platform Operations and MLOps](https://www.bionconsulting.com/ai-platform-operations-and-mlops-on-aws)
- Observability & Monitoring 
    - [New Relic](https://www.bionconsulting.com/partnerships/new-relic)
    - [Application Performance Monitoring](https://www.bionconsulting.com/new-relic/application-performance-monitoring)
    - [Observability for DevOps Teams](https://www.bionconsulting.com/new-relic/observability-for-devops-teams)
    - [New Relic Health Check](https://www.bionconsulting.com/services/new-relic/observability-health-check)
    - [SAP Monitoring with New Relic](https://www.bionconsulting.com/partnerships/new-relic/sap-monitoring-with-new-relic)
    - [Migration from Datadog](https://www.bionconsulting.com/partnerships/new-relic/migration-from-datadog)
- Industries 
    - [Financial Services & Insurance](https://www.bionconsulting.com/industries/financial-services-insurance)
    - [SaaS & ISV](https://www.bionconsulting.com/industries/saas-isv)
    - [Retail & E-commerce](https://www.bionconsulting.com/industries/retail-e-commerce)
    - [Travel & Hospitality](https://www.bionconsulting.com/industries/travel-hospitality)
    - [Healthcare & Life Sciences](https://www.bionconsulting.com/industries/healthcare-life-sciences)
    - [Education & EdTech](https://www.bionconsulting.com/industries/education-edtech)
    - Startups 
          - [DaaS for Startups](https://www.bionconsulting.com/startups/devops)
          - [AWS Migration for Startups](https://www.bionconsulting.com/startups/aws-migration)
- Partnerships 
    - [AWS](https://www.bionconsulting.com/partnerships/aws)
    - [New Relic](https://www.bionconsulting.com/partnerships/new-relic)
    - [Anchore](https://www.bionconsulting.com/partnerships/anchore)
    - [Octopus](https://www.bionconsulting.com/partnerships/octopus)
    - [DBmaestro](https://www.bionconsulting.com/partnerships/dbmaestro)
    - [Eclypses](https://www.bionconsulting.com/partnerships/eclypses)
    - [Vanta](https://www.bionconsulting.com/partnerships/vanta)
    - [Palo Alto](https://www.bionconsulting.com/partnerships/palo-alto)
- [About us](https://www.bionconsulting.com/about)
- [Case Studies](https://www.bionconsulting.com/case-studies)
- [Blog](https://www.bionconsulting.com/blog)
- [Contact us](https://www.bionconsulting.com/contact-us)

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

# Detecting Threats and Securing the Kubernetes Environment with Falco

[Bion DevOps Team](https://www.bionconsulting.com/blog/author/bion-devops-team)

 Mar 15, 2022, 10:03:22 AM

<https://twitter.com/intent/tweet?url=&text=https://www.bionconsulting.com/blog/detecting-threats-and-securing-the-kubernetes-environment-with-falco>

<https://www.linkedin.com/shareArticle?mini=true&url=https://www.bionconsulting.com/blog/detecting-threats-and-securing-the-kubernetes-environment-with-falco>

We are always looking for best practices while working with the Kubernetes cluster to secure our system. Also, we use 2FA's, Container Image Scanning and Network Policy to prevent intrusions. Sometimes, it can be hard to keep our system secure despite all these precautions. And when attacks happen, it's crucial to detect threats and respond as quickly as possible in order to secure our Kubernetes environment. In this blog post, we'll explore using open-source [Falco](https://github.com/falcosecurity/falco) to detect unexpected behaviour and alerts on threats at runtime.

 

![](https://www.bionconsulting.com/hs-fs/hubfs/Google%20Drive%20Integration/Bion%20Consulting-Detecting%20Threats%20and%20Securing%20the%20Kubernetes%20Environment%20with%20Falco.png?width=449&name=Bion%20Consulting-Detecting%20Threats%20and%20Securing%20the%20Kubernetes%20Environment%20with%20Falco.png)

## What is Falco?

Falco is an open-source, first Cloud-Native Runtime Security project, IDS (Intrusion Detection Systems) and behavioural activity monitor tool. Falco was created by Sysdig in 2016. Falco helps us check Linux kernel, container, Kubernetes and other logs and raise alerts for unwanted usage. Falco detects runtime unexpected application behaviours at the kernel level and issues alerts about threats.

Falco can consume events from different sources and apply rules to these events to detect abnormal behaviours. One of the event sources is syscalls which detects with drivers. Currently, the Falco project has three different kinds of drivers such as the Kernel module, which is the default driver for Falco, [eBPF](https://ebpf.io/) probe and Userspace instrumentation. For detailed information, please visit [here.](https://falco.org/docs/event-sources/drivers/) 

The other event source is Kubernetes audit logs. Falco uses Kubernetes audit logs to capture threat findings and raises alerts on the results it receives. In this way, we can view who is logging into the cluster and what dangerous behaviour they are doing in the cluster.

![](https://www.bionconsulting.com/hs-fs/hubfs/Google%20Drive%20Integration/Bion%20Consulting-Detecting%20Threats%20and%20Securing%20the%20Kubernetes%20Environment%20with%20Falco.jpeg?width=787&name=Bion%20Consulting-Detecting%20Threats%20and%20Securing%20the%20Kubernetes%20Environment%20with%20Falco.jpeg)

*(Source: [https://sysdig.com/](https://sysdig.com/))*

At the core of Falco is a list of rules*.* These rules govern all events in a Kubernetes cluster. Here are some events Falco checks:

- Container running in privileged mode
- A server process that creates a new child process
- Any resource that reads a sensitive file
- The starting of the new privileged pod

## What are Rules?

A Falco rules file is a YAML file. A rule file contains three types of elements: 

- Rule
- Macro  
- List

Rules consist of key fields such as **description**, **condition**, **output** and **priority**. The condition field is a filtering expression that is applied against events to check whether they match the rule, under which alerts should be generated. It has another field named output, which contains the string that is sent with the alert.

Macros are reusable mini-rules. They are used to create rules quickly and predictably. Instead of redefining the sub-portions, we can define them as macro and use them in more than one condition. You will find an example of this below.

Lists are collections of items that you can include in rules, macros or even other lists.

Let’s explain the condition with an example. Let’s say we want to detect if any of our node.js containers run any processes which are not node.js binary. So, we’re going to write this:

```
 condition: evt.type=execve and k8s.deployment.name=my_node_app and proc.name!= node
```

Let’s explain how Falco reads each part of the condition here:

- **evt.type=execve** → If something is executing a program
- **k8s.deployment.name=my\_node\_app** → If the process is running in a container in my Kubernetes deployment named my\_node\_app
- **proc.name!= node** → If the running process name isn’t node (node.js binary files)

You can use many field classes to create conditions such as evt as in evt.type or k8s as in k8s.deployment.name. To check the list please visit [here](https://falco.org/docs/rules/supported-fields/).

Here's another example of a condition that alerts whenever a bash shell is run inside a container successfully:

```
 - rule: shell_in_container
  desc: notice shell activity within a container
  condition: evt.type = execve and evt.dir=< and container.id != host and proc.name = bash
  output: shell in a container (user=%user.name container_id=%container.id container_name=%container.name shell=%proc.name 
parent=%proc.pname cmdline=%proc.cmdline)
  priority: WARNING 
```

Let’s take a look at another example with macros. Falco can hook the kube-api events. In this example, we can detect if someone is creating or modifying a config map that has some private credential inside rather than using it as a secret.

```
 - macro: contains_private_credentials
  condition: > 
   (ka.req.configmap.obj contains "aws_access_key_id" or
    ka.req.configmap.obj contains "aws_s3_key_id" or
    ka.req.configmap.obj contains "password")
- macro: configmap
  condition: ka.target.resouce=configmaps
- macro: modify
  condition: (ka.verb in (create,update,patch))
- rule: Create/modify Configmap with private credentials
  desc: Detect creating/modifying a configmap containing a private credential (aws key, password, etc.)
  condition: configmap and modify and contains_proivate_credentials
  output: K8s configmap with private credential (user=%ka.user.name 
         verb=%ka.verb name=%ka.req.configmap.name configmap=%ka.req.configmap.name config=%ka.req.configmap.obj)
  priority: WARNING
  source: k8s_audit
  tags: [k8s]
```

In this example, we used macros to simplify the condition of the rule.

As mentioned before, if any rule in Falco is violated, it triggers an alert. By default, Falco has 5 outputs for its events: **stdout**, **file**, **gRPC**, **shell** and **HTTP**. Even if they're convenient, we can quickly be limited to integrating Falco with other components. This is where [Falcosidekick](https://github.com/falcosecurity/falcosidekick) comes into play. Falcosidekick is a little daemon that extends that number of possible outputs. It manages a large variety of outputs with different purposes such as Slack, Teams and Discord for Chat, Datadog and Prometheus for Metrics, OpsGenie and PagerDuty for Alerting, etc. To see the whole list please visit [here](https://github.com/falcosecurity/falcosidekick#outputs).

## Now, Let’s Get Our Hands Dirty! Installation

We can deploy Falco on a local machine, cloud, a managed Kubernetes cluster or a Kubernetes cluster such as K3s running on IoT & Edge computing. 

One of the easiest ways to install Falco is to use Helm. 

After making sure [Helm](https://helm.sh/docs/intro/install/#from-script) is installed, let’s continue to install the Falco with notification-daemon Falcosidekick. We have a cluster with 2 nodes that we will use for the demo. 

| controlplane $ kubectl get nodes NAME           STATUS   ROLES    AGE   VERSION controlplane   Ready    master   76s   v1.18.0 node01         Ready    <none>   43s   v1.18.0 |
| --- |

Next, we need to add falcosecurity to the Helm repo, update and install it. We’ll use Slack as an output in this demo. So, please don't forget to change the Slack webhook URL while installing it.

| controlplane $ helm repo add falcosecurity https://falcosecurity.github.io/charts "falcosecurity" has been added to your repositories |
| --- |

 

| controlplane $ helm repo update Hang tight while we grab the latest from your chart repositories... ...Successfully got an update from the "falcosecurity" chart repository Update Complete. ⎈Happy Helming!⎈ |
| --- |

 

| controlplane $ helm install falco falcosecurity/falco \\               --set falcosidekick.enabled=true \\               --set falcosidekick.config.slack.webhookurl="https://hooks.slack.com/services/XXXX" \\               -n falco NAME: falco LAST DEPLOYED: Tue Feb  13 04:03:40 2022 NAMESPACE: falco STATUS: deployed REVISION: 1 TEST SUITE: None NOTES: Falco agents are spinning up on each node in your cluster. After a few seconds, they are going to start monitoring your containers looking for security issues. No further action should be required. |
| --- |

Falco is applied once per node because it is deployed as a DaemonSet in the cluster. To check the status of Falco pods: 

| controlplane $ kubectl get pods -n falco NAME                                   READY   STATUS    RESTARTS   AGE falco-82sjs                            1/1     Running   0          5m31s falco-falcosidekick-77b486f847-4smm7   1/1     Running   0          5m32s falco-falcosidekick-77b486f847-tghq2   1/1     Running   0          5m31s falco-j829h                            1/1     Running   0          5m32s |
| --- |

We have successfully installed Falco.  
Let’s Test Falco!  
First, create an httpd pod with imperative command and run an exec command for that pod.

| ​​controlplane $ kubectl run httpd --image=httpd pod/httpd created |
| --- |

 

| controlplane $ kubectl get pod httpd NAME    READY   STATUS    RESTARTS   AGE httpd   1/1     Running   0          105s node01 $ kubectl exec -it pod/httpd -- bash -il root@httpd:/usr/local/apache2# |
| --- |

Now, let's take a look at the channel we set as incoming webhook on Slack.

![Falco](https://lh5.googleusercontent.com/Ghnq1BT8m73AksceWF26YQLQdsZANtEIw3scPpste77yna-FiXkA43MX9W9gyTFCW7Nam6tVI94LWEK_i7udatyQYhv8bk9wk-nctFvoT5C-Ts9qBkZx5yAk8ayK6ciDikeOeZQ3)

As you can see, Falco caught the bash command we were running when using the exec command and informed us about the activities in our system. From now on, Falco will notify us if there is any "dangerous" behaviour in our system.

Falco is a great behavioural activity monitor tool for Kubernetes clusters. By using this tool, you can be instantly informed about what is happening in your cluster. In this article, we briefly talked about how a rule is created for Falco. Once you understand the logic of the rule, the limit will be your imagination. 

[Kubernetes](https://www.bionconsulting.com/blog/tag/kubernetes) [K8S](https://www.bionconsulting.com/blog/tag/k8s) [Falco](https://www.bionconsulting.com/blog/tag/falco)

## Leave a Comment

## Related Posts

### [Jan 9, 2023, 8:52:45 PM Database DevOps - Why you should do it](https://www.bionconsulting.com/blog/database-devops)

### [Jan 20, 2021, 12:11:48 PM Kubernetes Network Policies - Part 1](https://www.bionconsulting.com/blog/kubernetes-network-policies)

### [Jul 8, 2026, 4:15:00 PM Monitoring and Gathering Metrics from Kubernetes Audit Logs](https://www.bionconsulting.com/blog/monitoring-and-gathering-metrics-from-kubernetes-auditlogs)

![bion-logo-white-122x40](https://www.bionconsulting.com/hubfs/bion-logo-white-122x40.png)

Bion Consulting helps organisations build secure, scalable, and high-performing cloud environments. With deep expertise in DevOps, security, containerisation, observability, and AI platform operations, we deliver resilient solutions for complex and evolving business needs.

<https://twitter.com/teambion> <https://www.linkedin.com/company/bionconsulting>

- [Home](https://www.bionconsulting.com)
- [DevOps](https://www.bionconsulting.com/devops-as-a-service)
- [AWS](https://www.bionconsulting.com/partnerships/aws)
- [New Relic](https://www.bionconsulting.com/partnerships/new-relic)
- [Octopus](https://www.bionconsulting.com/partnerships/octopus)
- [DBmaestro](https://www.bionconsulting.com/partnerships/dbmaestro)
- [Anchore](https://www.bionconsulting.com/partnerships/anchore)
- [About us](https://www.bionconsulting.com/about)
- [Contact Us](https://www.bionconsulting.com/contact-us)

 © 2026 All rights reserved.