detecting-container-runtime-threats-with-falco
mukul975/Anthropic-Cybersecurity-Skills
Deploy and operate Falco with the modern eBPF driver in Kubernetes and Docker. Covers driver selection, Helm installation, output channels, and the built-in ruleset that detects container escape, namespace abuse, privileged mounts, and anomalous syscalls. Ideal for enabling runtime security, routing alerts to SIEM or Falcosidekick, and upgrading existing deployments.