
Runtime Protection with Sysdig/Falco
Complete Runtime Protection with Sysdig/Falco in a deterministic practice workspace without depending on unavailable host, cloud, hardware, desktop, or multi-node infrastructure.
Briefing
Objectives
- 1Prepare workspace and verify tooling
- 2Prepare local target for Runtime Protection with Sysdig/Falco
- 3Execute Runtime Protection with Sysdig/Falco technique
- 4Capture evidence
- 5Complete Falco Deployer
- 6Complete Process Monitor
- 7Tune and interpret
- 8Compile and verify submission
Flags
Submit the verifiable output value for Falco Deployer as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the verifiable output value for Process Monitor as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the verifiable output value for Auto Responder as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the verifiable output value for SIEM Integrator as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the verifiable output value for File Watcher as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).