Falco, the CNCF-graduated open-source runtime security tool, can now be integrated with AWS Security Hub CSPM via an AWS Marketplace listing. The solution deploys Falco on EKS clusters using eBPF to monitor syscalls at the kernel level, forwarding alerts through FalcoSidekick → CloudWatch → Lambda → Security Hub in AWS Security Finding Format (ASFF). The Marketplace offering automates the entire setup — IAM roles, Lambda functions, CloudWatch log groups, and Falco Helm chart deployment — reducing what was previously a complex multi-service configuration to a ~10-minute deployment. Detections include shell spawns in containers, sensitive file access, privilege escalation, and unusual network activity, all surfaced as categorized findings in AWS Security Hub alongside GuardDuty, Inspector, and other AWS security services.

6m read timeFrom webflow.sysdig.com
Post cover image
Table of contents
What is Falco?The challenge: Making OSS runtime security AWS-nativeWait…what is AWS Security Hub CSPM?The solution: Falco + AWS Security Hub CSPM integration via AWS MarketplaceReal-world detection examplesGetting startedConclusion
3 Impressions