Curating Falco rules with MITRE ATT&CK Matrix
-
Updated
Mar 7, 2024 - Python
Curating Falco rules with MITRE ATT&CK Matrix
Production-grade IDP on EKS built with AI in 3 hours. 27 components, 59 tests, honest scorecard. Reusable template included.
Enterprise SOC Platform for Detection Engineering, IAM Governance, SOAR Automation, UEBA, Threat Intelligence, Compliance Auditing and Hybrid Infrastructure Security Monitoring.
Production-ready application stack - unified, secure, automated deployment for security-cognizant self-hosters. Microsoft Entra ID integration - designed for ease-of-use and architectural transparency to encourage all skill levels to experiment with Docker/Kubernetes clusters.
CMMC Level 2 security automation lab built on AWS/RKE2 with FreeIPA, AWX, NetBox, Splunk, GitLab CE, Prometheus, Falco, and AIDE
Repository for the Seguridad y Privacidad en TI (SPTI) course at Escuela Colombiana de Ingeniería Julio Garavito. Covers OSINT, threat modeling, ethical hacking, cryptography, malware analysis, and DevSecOps through hands-on labs and security automation pipelines.
Proof-carrying cyber immunity for Linux containers: signed evidence, deterministic policy, local approval and exact TTL containment.
Applied STRIDE to threat model a microservice env.–defining the security architecture and attack surfaces; hardened the app’s Docker environment using Docker-bench, created an RKE cluster, and hardened a Kubernetes cluster using Grype and Trivy. Also implemented runtime monitoring using Grafana to visualize runtime security alerts via Sysdig Falco.
Research-grade Smart City IDS on Kubernetes: Falco + Suricata detection, LLM-assisted alert analysis with failover, governance-controlled response automation, and IoT protocol emulation.
AI-powered Falco rule generator, explainer & validator — a missing feature in the CNCF Falco ecosystem
eBPF-based runtime threat detection engine (Falco-like)
Microservices Security project of the Udacity's Cloud Native Application Architecture Nanodegree
Runtime security platform for Kubernetes Falco with 14 MITRE ATT&CK-mapped detection rules, OPA Gatekeeper admission control, Kyverno policy engine with Cosign image verification, Trivy Operator continuous CVE scanning, automated incident response with pod isolation and forensic capture, and Prometheus alerting. CIS K8s Benchmark 1.8 compliant.
A per-node Falco DaemonSet using the modern eBPF driver, structured JSON events and the upstream least-privileged driver configuration
Event-driven Kubernetes runtime security platform with automated quarantine, AI-based behavior analysis, and incident forensics
Laptop-friendly, Linux-first mini-SOC with detection-as-code: Wazuh + Suricata + Falco + honeypots, every detection validated in CI by replaying the real attack
CLI tools for Kubernetes operations and AI infrastructure — triage, security scanning, runtime replay, socket inspection, and AI agent workspace generation.
To associate your repository with the falco topic, visit your repo's landing page and select "manage topics."