KubeCon + CloudNativeCon Europe

Project Lightning Talk: Forensics With Falco - Gerald Combs, Maintainer

4:57 · 23 Mar 2026 – 26 Mar 2026 · YouTube

About this talk

In this talk, Gerald Combs, the creator of Wireshark, introduces Falco, a cloud-native real-time threat detection engine primarily used in Kubernetes clusters. He emphasizes Falco's capability to monitor system calls and log messages, triggering alerts based on predefined rules. Recently, Falco included a feature to save triggering activity to capture files, allowing deeper investigative analysis with StratoShark, a tool he has developed that parallels Wireshark's capabilities. Combs explains how to configure Falco to enable this capture feature and discusses considerations such as performance and configuration nuances. He shares insights from a previous demo and encourages community feedback on the new features while inviting attendees to see a live demo at KubeCon.

Full transcript

I am Gerald Combs. I'm more well known as the creator and lead developer of Wireshark, but I am also a Falco maintainer and Whoop. What did I do? I'm sorry, hold on. Uh first of all, Falco, if you're not familiar with it, is a cloud-native real-time threat detection engine. Uh typically, you would deploy it in a Kubernetes cluster and it will sit there and monitor your system

calls and log messages and match them against a set of rules. And if any of those rules trigger, you get an alert. Um Falco does a great job with this. A lot of people use it and have been for the last 10 years. It's about to celebrate its 10-year anniversary. But one of the neat things that we added in Falco recently was the ability to take that

activity whenever it triggers one of those rules and save it out to a capture file. And the idea behind that is to let you then do more investigative analysis using a tool called StratoShark, which is something that I've been working on. StratoShark is a sibling application of Wireshark that lets you do more investigative analysis. It uses the same user interface as Wireshark. It uses the same dissection

engine. So, you can take all these workflows that you would normally use in the packet world and apply them to system calls and log messages. And so, you know, the idea is that we take a really nice workflow that we have on the networking side and we've had for, I don't know, the past 20 25 years where you have all these tools that are based around libpcap

and its file formats. And, you know, you would kind of move that over and replicate that on the system call side with with Falco and StratoShark and, you know, the libraries that they use and hopefully more applications will pop up over time. Now, last year at uh KubeCon North America, I gave a demo of using StratoShark with Falco and um I I focused mainly on the StratoShark

side and and I finished up the talk showing that the that you can actually use these tools to look at data that was transmitted across a pipe. Uh in this case, somebody was trying to exfiltrate an SSH key, but I didn't really talk about the Falco side of this and and uh if you'll indulge me, that's what I'd like to do here today. On the Falco side,

you need to make some changes to Falco's configuration file, which is falco.yaml by default. And Falco's configuration is documented in the URL you see at the top of the the screen. But to enable capture, you have to go down to the capture section and say enable true. It's It's It's false by by default just because we want Falco to be as lightweight as possible by default. And

then you have a choice. You can either enable these capture files for all of Falco's rules or just a specific set of rules that that that you you know may desire. You also need to tell Falco where to save these files out. So you know you can specify a path prefix. By default that's /tmp/falco. And most importantly, you need to tell Falco when to stop saving out

this information. And uh And you can do that by right now by specifying a time duration in milliseconds. Future version of Falco will also let you specify and and uh the number of events to capture or you can tell it to stop when it reaches a particular file size. And once you have all this set up and enabled, anytime a rule triggers, you'll end up these timestamp

capture files that you see at the bottom that have a similar format. Um now for the demo that I did last fall, I actually had to enable a bit more information. I had to tell Falco to uh do a bit more analysis and explicitly capture read and write system calls. Normally that has a lot of overhead, so we have it off by default and and told it

to expand its uh its state engine a little bit and some other things. And this is something you might want to if you want to play with, you might want to take care because you can run into something called the observer effect where if you're monitoring a system, you can affect the performance of that system. Um I know in the networking world where I come from, you

can kind of throw money at this problem and and buy passive hardware taps. Uh, unfortunately, I was very disappointed to learn that you cannot buy passive hardware taps for system calls on a CPU. Um, that stinks. But, uh, if you do want to play around with this, you just have to, you know, keep this in mind and uh, do a bit of experimentation and and maybe apply

some thought. And as the slide says, your feedback on this feature would be really useful here. I mean, it it's still is a new thing and it is still under development. if you want to learn more about this and if you want to actually see a live demo, I would be happy to give it to you at the Falco booth here at KubeCon. You can also find

more at the the URLs on the screen. And tomorrow there'll be a a much more in-depth presentation on Falco and room G102 at noon. Um, finally, I just wanted to say thank you. I love being part of these communities. Being part of these communities has given me a wonderful career and a very rewarding career and it's all down to our users. So, thank you very much. Awesome.

Thank you very much, Gerald.