<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Falco – Live Event</title><link>https://v0-43--falcosecurity.netlify.app/tags/live-event/</link><description>Recent content in Live Event on Falco</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Wed, 18 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://v0-43--falcosecurity.netlify.app/tags/live-event/feed.xml" rel="self" type="application/rss+xml"/><item><title>Blog: Falco at KubeCon Europe 2026 — See You in Amsterdam! 🐦</title><link>https://v0-43--falcosecurity.netlify.app/blog/kubecon-eu-2026/</link><pubDate>Wed, 18 Mar 2026 00:00:00 +0000</pubDate><guid>https://v0-43--falcosecurity.netlify.app/blog/kubecon-eu-2026/</guid><description>
&lt;p&gt;We're excited to share that the Falco community will be at &lt;strong&gt;KubeCon + CloudNativeCon Europe 2026&lt;/strong&gt; in Amsterdam! Whether you're a long-time contributor, a curious user, or just want to say hi, we'd love to see you there.&lt;/p&gt;
&lt;p&gt;&lt;img src="images/falco-ten-year-badge.png" alt="Falco 10 years badge" loading="lazy" /&gt;
&lt;/p&gt;
&lt;p&gt;Falco is celebrating &lt;strong&gt;10 years&lt;/strong&gt; of development and adoption, and we are on the lookout for people who would like to say Happy Birthday to the project or share their best Falco story. Libby Schulze and I will be on the event floor with mic and camera to capture some amazing moments and memories from Falco's 10 years. So bring your best story, and we'll see you at the Falco booth!&lt;/p&gt;
&lt;h2 id="sneak-peek"&gt;Sneak peek&lt;/h2&gt;
&lt;p&gt;Psst... we have something really cool brewing that we will show at the Falco booth. You, our amazing reader, is the first to hear about this. It's a way to run Falco locally on your development machine, and make sure your AI coding agents are following new rules that are being defined. We'd love to get your feedback on this as we're currently building it!&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Here’s where you can find us in Amsterdam and everything we have lined up:&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="project-lightning-talk"&gt;Project lightning talk&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://kccnceu2026.sched.com/event/2EFx1/project-lightning-talk-forensics-with-falco-gerald-combs-maintainer"&gt;&lt;strong&gt;Forensics With Falco&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;Speaker:&lt;/strong&gt; Gerald Combs, Maintainer&lt;br&gt;
&lt;strong&gt;When:&lt;/strong&gt; Monday, March 23, 2026 — 10:27 to 10:32 CET&lt;br&gt;
&lt;strong&gt;Where:&lt;/strong&gt; Elicium 2&lt;/p&gt;
&lt;p&gt;Falco has recently expanded its capabilities with capture recording, opening the door to seamless integration with forensic analysis tools like Stratoshark. In this lightning talk, Gerald will walk through how the two tools work together to provide deep visibility into container and system activity. He will demonstrate how captured event data can accelerate investigations and discuss key considerations for safely and efficiently deploying these features in production environments.&lt;/p&gt;
&lt;h2 id="sysdig-led-workshop"&gt;Sysdig-led workshop&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://sysdig.pathfactory.com/kceu26-falco-workshop/"&gt;&lt;strong&gt;Hands-On Cloud Native Security Workshop&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;When:&lt;/strong&gt; Monday, March 23 — 2:00–4:00 PM CET&lt;/p&gt;
&lt;p&gt;Run Atomic Red Team™ tests, then step into the Blue Team role to detect threats and create custom Falco™ detection rules in this hands‑on 90‑minute keyboard workshop.&lt;/p&gt;
&lt;h2 id="conference-talk"&gt;Conference talk&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://kccnceu2026.sched.com/event/2EF6W/in-falcos-nest-the-evolution-of-cloud-native-runtime-security-iacopo-rozzo-sysdig-aldo-lacuku-kong-inc"&gt;&lt;strong&gt;In Falco's Nest: The Evolution of Cloud Native Runtime Security&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;Speakers:&lt;/strong&gt; Iacopo Rozzo (Sysdig), Aldo Lacuku (Kong Inc.)&lt;br&gt;
&lt;strong&gt;When:&lt;/strong&gt; Tuesday, March 24, 2026 — 12:00 to 12:30 CET&lt;br&gt;
&lt;strong&gt;Where:&lt;/strong&gt; G102–103&lt;/p&gt;
&lt;p&gt;Falco, the Cloud Native Runtime Security project, is constantly evolving to meet the demands of modern cloud environments. This maintainer track session, led by the Falco maintainers, will dive deep into the latest advancements and the strategic direction of the project. We will focus on two major areas of growth: the introduction of the new Falco Operator and the new features that enhance Falco's performance and reliability.&lt;/p&gt;
&lt;p&gt;The new Falco Operator simplifies the deployment, configuration, and management of Falco across Kubernetes clusters, making it easier than ever for users to secure their runtime environments at scale.&lt;/p&gt;
&lt;p&gt;Furthermore, we will explore the most significant new features integrated into Falco. This includes performance optimizations for high-throughput environments. The session will also touch upon community contributions, ecosystem integrations, and the roadmap for the upcoming release.&lt;/p&gt;
&lt;h2 id="booth-demo"&gt;Booth demo&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Pivoting from detection to investigation with Falco and Stratoshark&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Speaker:&lt;/strong&gt; Gerald Combs&lt;br&gt;
&lt;strong&gt;When:&lt;/strong&gt; Tuesday, March 24, 2026 — 15:45 CET&lt;br&gt;
&lt;strong&gt;Where:&lt;/strong&gt; Sysdig Booth #671&lt;/p&gt;
&lt;p&gt;See how to move from “we detected something” to “here’s what happened” using Falco and Stratoshark. Stop by the Sysdig booth and say hello!&lt;/p&gt;
&lt;h2 id="thank-you"&gt;Thank you!&lt;/h2&gt;
&lt;p&gt;We couldn’t do this without you all in our community - the contributors, users, and everyone who shows up at events. If you’re in Amsterdam, come find us at the talks, the workshop, or the booth. We’d love to meet you and hear how you’re using Falco.&lt;/p&gt;
&lt;p&gt;See you there! 🐦&lt;/p&gt;</description></item><item><title>Blog: Falco at the KubeCon NA 2022</title><link>https://v0-43--falcosecurity.netlify.app/blog/falco-kubecon-2022/</link><pubDate>Tue, 08 Nov 2022 00:00:00 +0000</pubDate><guid>https://v0-43--falcosecurity.netlify.app/blog/falco-kubecon-2022/</guid><description>
&lt;p&gt;It was KubeCon recently. I doubt anyone reading this didn't know about it. And if you attended, you're probably still receiving e-mails about the event.&lt;/p&gt;
&lt;p&gt;KubeCon is where everyone wants to be. And Falco was there too. It did indeed have a great presence: A project meeting, mentions, a few presentations, a keynote, it even had a party!&lt;/p&gt;
&lt;p&gt;Once there, it was Falco time!&lt;/p&gt;
&lt;h2 id="project-meeting"&gt;Project Meeting&lt;/h2&gt;
&lt;!-- Tuesday, Oct 25 | 13:00 - 17:00 --&gt;
&lt;p&gt;A project meeting is where maintainers of the project, users, adopters and contributors have the opportunity to exchange impressions. On Tuesday afternoon, Falco maintainers met with interested users and potential adopters, and presented, not only the background of the project, but also its future roadmap.&lt;/p&gt;
&lt;p&gt;There were questions from the attendees, requests and announcements of upcoming features, and even live demos. From the new plugins framework till the recent gVisor support, including a deep explanation of Falco libraries' insights. If you didn't know how Falco worked internally, you could leave the room being an expert.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://v0-43--falcosecurity.netlify.app/blog/falco-kubecon-2022/images/falco-at-kubecon-na-2022-01.png" alt="Falco Project Meeting at KubeCon NA 2022" loading="lazy" /&gt;
&lt;/p&gt;
&lt;h2 id="presentations"&gt;Presentations&lt;/h2&gt;
&lt;p&gt;Falco is a well known project. It was mentioned in at least five presentations. Some of these, delivered by the core maintainers. Others, by the community or the CNCF organization itself. Its presence in so many occasions reflected the project's reputation in the community.&lt;/p&gt;
&lt;h3 id="keynote"&gt;Keynote&lt;/h3&gt;
&lt;p&gt;Tuesday morning. Still tired from the jet-lag, and after the first day of Cloud Native SecurityCon, our first public Falco moment of the day: A Keynote at the SecurityCon delivered by &lt;strong&gt;Loris Degioanni&lt;/strong&gt;, original creator of Falco.&lt;/p&gt;
&lt;p&gt;Loris introduced the new &lt;a href="https://v0-43--falcosecurity.netlify.app/blog/falco-plugin-github/"&gt;GitHub Plugin for Falco&lt;/a&gt;, which is capable of detecting events like using GitHub actions for cryptominers, pushing code with secrets, or even detecting when someone starred the repository.&lt;/p&gt;
&lt;p&gt;The time dedicated to a keynote is usually short, but for Loris it seemed to be enough to perform a couple of live demos. Don't miss them in this video.&lt;/p&gt;
&lt;p&gt;
&lt;div style="position: relative; padding-bottom: 45%; height: 0; overflow: hidden;"&gt;
&lt;iframe src="https://www.youtube.com/embed/o3Mz3ha3gMM" style="position: absolute; top: 0; left: 0; width: 80%; height: 100%; border:0;" allowfullscreen title="Detecting Threats in GitHub with Falco - Loris Degioanni"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;a href="https://www.youtube.com/watch?v=o3Mz3ha3gMM"&gt;Detecting Threats in GitHub with Falco - Loris Degioanni&lt;/a&gt;&lt;/p&gt;
&lt;h3 id="the-eye-of-falco"&gt;The Eye of Falco&lt;/h3&gt;
&lt;p&gt;That same day, a few hours later, &lt;strong&gt;Stefano Chierici&lt;/strong&gt;, &lt;em&gt;Senior Security Researcher&lt;/em&gt;, and &lt;strong&gt;Lorenzo Susini&lt;/strong&gt;, &lt;em&gt;Open Source Engineer&lt;/em&gt;, both contributors of Falco, presented one of the most exciting of its features: Detection of attempts to escape Linux capabilities.&lt;/p&gt;
&lt;p&gt;During this presentation, Lorenzo did an extensive walkthough on Linux capabilities, explaining the security situation before having them, detailing on its different sets (effective, permitted and inheritable) and its security implications when creating new processes that require higher privileges.&lt;/p&gt;
&lt;p&gt;Stefano, on the other side, walked us through different scenarios showing a variety of real attacks. Therefore, having the CAP_SYS_MODULE capability enabled in the container would allow an attacker to use a Kernel Module to attack; having the CAP_SYS_PTRACE capability active would allow the injection of malicious code into memory; and having the CAP_SYS_ADMIN capability might open more than one path to make our host exploitable.&lt;/p&gt;
&lt;p&gt;Trying not to spoil the end of the presentation (you can already imagine it though), we recommend to watch the following video to see how Falco faces this kind of threats, as it does with many others, by obtaining the state of the container and warning the user if the capabilities exceed the desirable ones.&lt;/p&gt;
&lt;!-- (Oct 25, 2022 | 15:40 - 16:10) --&gt;
&lt;p&gt;
&lt;div style="position: relative; padding-bottom: 45%; height: 0; overflow: hidden;"&gt;
&lt;iframe src="https://www.youtube.com/embed/j3PcSGlJcZI" style="position: absolute; top: 0; left: 0; width: 80%; height: 100%; border:0;" allowfullscreen title="The Eye of Falco: You Can Escape but Not Hide - Stefano Chierici &amp;amp; Lorenzo Susini"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;a href="https://www.youtube.com/watch?v=j3PcSGlJcZI"&gt;The Eye of Falco: You Can Escape but Not Hide - Stefano Chierici &amp;amp; Lorenzo Susini&lt;/a&gt;&lt;/p&gt;
&lt;h3 id="detecting-the-undetectable"&gt;Detecting the Undetectable&lt;/h3&gt;
&lt;p&gt;Falso also squeezed into a presentation from &lt;strong&gt;Carol Valencia&lt;/strong&gt;, &lt;em&gt;Cloud Native Security Advocate at Aqua Security&lt;/em&gt;, where she demonstrated how three different runtime security solutions, Falco among them, were able to detect fileless attacks.&lt;/p&gt;
&lt;p&gt;
&lt;div style="position: relative; padding-bottom: 45%; height: 0; overflow: hidden;"&gt;
&lt;iframe src="https://www.youtube.com/embed/dizRKAjuhS0" style="position: absolute; top: 0; left: 0; width: 80%; height: 100%; border:0;" allowfullscreen title="Fileless Attack - Detecting the Undetectable"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;a href="https://www.youtube.com/watch?v=dizRKAjuhS0"&gt;Fileless Attack - Detecting the Undetectable&lt;/a&gt;&lt;/p&gt;
&lt;h3 id="falco-project-updates"&gt;Falco Project Updates&lt;/h3&gt;
&lt;p&gt;For those that were not able to attend the Project Meetings at the SecurityCon, KubeCon was a second great opportunity to learn from their favority CNCF projects.&lt;/p&gt;
&lt;p&gt;On Friday afternoon, &lt;strong&gt;Jason Dellaluce&lt;/strong&gt; and &lt;strong&gt;Luca Guerra&lt;/strong&gt;, both &lt;em&gt;Open Source Engineers&lt;/em&gt;, as well as Falco maintainers, gave an overview of the Falco project and its recent updates.&lt;/p&gt;
&lt;p&gt;
&lt;div style="position: relative; padding-bottom: 45%; height: 0; overflow: hidden;"&gt;
&lt;iframe src="https://www.youtube.com/embed/pDwmWFa9oAQ" style="position: absolute; top: 0; left: 0; width: 80%; height: 100%; border:0;" allowfullscreen title="Security In the Cloud With Falco: Overview And Project Updates - Jason Dellaluce &amp;amp; Luca Guerra"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;a href="https://www.youtube.com/watch?v=pDwmWFa9oAQ"&gt;Security In the Cloud With Falco: Overview And Project Updates - Jason Dellaluce &amp;amp; Luca Guerra&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="https://v0-43--falcosecurity.netlify.app/blog/falco-kubecon-2022/images/falco-at-kubecon-na-2022-03.png" alt="Falco Updates at KubeCon NA 2022" loading="lazy" /&gt;
&lt;/p&gt;
&lt;h2 id="falco-kiosk-at-the-cncf-pavillion"&gt;Falco Kiosk at the CNCF Pavillion&lt;/h2&gt;
&lt;p&gt;This year at the KubeCon, Falco maintainers spent a good amount of time at the Falco kiosk. They received visitors interested in the project, some, already users of Falco, others, new users looking to learn about it, even a couple of youtubers asking to interview the maintainers for their channels.&lt;/p&gt;
&lt;p&gt;All in all, an awesome chance to discover, first hand, what people really thought of Falco, wonders and pain points, good and not so good experiences with the tool and its ecosystem. In other words, real and valuable feedback.&lt;/p&gt;
&lt;h2 id="book-signing"&gt;Book signing&lt;/h2&gt;
&lt;p&gt;We haven't mentioned it yet, but Falco even had a book at the KubeCon. Shortly before the event, O'Reilly published &lt;a href="https://www.oreilly.com/library/view/practical-cloud-native/9781098118563/"&gt;Practical Cloud Native Security with Falco&lt;/a&gt;, written by &lt;strong&gt;Loris Degionni&lt;/strong&gt; and &lt;strong&gt;Leonardo Grasso&lt;/strong&gt;, both Falco maintainers with a large experience in the project.&lt;/p&gt;
&lt;p&gt;Wednesday and Thursday, Loris and Leo spent some time signing copies of their book to users and developers interested in learning the secrets of Falco. Receiving a book at the KubeCon is probably not such a highligh anymore. Receiving Falco users willing to queue to receive your book is still a rewarding experience though.&lt;/p&gt;
&lt;h2 id="party"&gt;Party&lt;/h2&gt;
&lt;!-- October 25th, 19:00-22:00 --&gt;
&lt;p&gt;KubeCon is not only about collecting swag and attending presentations, although these are a great source of knowledge (and the swag a lot of stolen space in your luggage). KubeCon is also about interacting with other attendees, having exciting conversations, sharing experiences and point of views.&lt;/p&gt;
&lt;p&gt;So Falco thought of using an evening to do exactly that!&lt;/p&gt;
&lt;p&gt;People at the event (let's call it a party!). So people at the party enjoyed some food, drinks, had meaningful conversations -at least, that's what we want to believe-, and played &lt;a href="https://cardsagainst.io/"&gt;Cards against Containers&lt;/a&gt; -the paper version, not the online one.&lt;/p&gt;
&lt;p&gt;Since the party took place on Tuesday, it meant a nice break between two days full of Security-related presentations, and the KubeCon starting the next day. We didn't stay long, but we had some joy.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://v0-43--falcosecurity.netlify.app/blog/falco-kubecon-2022/images/falco-at-kubecon-na-2022-04.png" alt="Falco Party at KubeCon NA 2022" loading="lazy" /&gt;
&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;As you can see, it was a week full of emotions, opportunities, friends and colleagues, and Falco. We are already looking forward to the next event, and we hope you too.&lt;/p&gt;
&lt;p&gt;And if you didn't get your copy of the book, maybe there'll be another chance next year in &lt;a href="https://events.linuxfoundation.org/cloudnativesecuritycon-north-america/"&gt;Seattle&lt;/a&gt; or &lt;a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/"&gt;Amsterdam&lt;/a&gt; ;-)&lt;/p&gt;</description></item></channel></rss>