Runtime Threat Detection with Falco thumbnail

Runtime Threat Detection with Falco

By Richard Augenti

Attack a running workload, watch the default Falco rules miss part of it, then write and tune custom rules that catch the behaviour without burying you in noise.

Browse
Skill Level: Intermediate Duration: 60 min Runtime SecurityKubernetesDevSecOps
Sign in to start

Free to browse. Takes about 60 minutes once you start.

Lab Overview

Everything up to here has been about stopping bad things from shipping. Some attacks only become visible when they run - a process reading a secret it should never touch, a credential-theft tool executing on a box you thought was fine.

In this lab you write detection rules for behaviour specific to your platform, load them into the kernel, and trigger them to confirm the detection actually fires. A detection nobody has fired on purpose is a detection you are hoping works.

A note on tooling: in production most teams run Falco for this, watching kernel activity through an eBPF probe with a rich rule language and Kubernetes awareness. This lab uses the kernel's built-in auditd instead, which needs no probe and works on any kernel, so you can focus on the detection-as-code idea itself. The concept is identical and what you learn here maps directly onto a Falco rule.

What to Expect

  • Environment: a single Ubuntu machine you connect to over SSH, with the kernel audit subsystem available and the target workload in place. No cluster required.
  • Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
  • Tooling: detections are written against auditd rather than Falco, so no probe or agent is installed. The rule-writing concepts transfer directly.
  • Progress: your work is not saved. If the lab expires or you quit, the machine and everything on it is destroyed.

What are hands-on labs?

A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.

Real tooling

The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.

Break it freely

Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.

Useful on Monday

Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.

Browse labs