Runtime Security and Detection Engineering
Learn to detect attacks in running containers with Falco, map detections to MITRE ATT&CK, test them, and route alerts to a safe, automated response.
What You'll Learn
Understanding Why Runtime Detection Is Needed
A clean image exploited at runtime The payment-service image at acme-shop passed every check.
Understanding eBPF in Plain Terms
What eBPF is and what it can see eBPF (extended Berkeley Packet Filter) lets small, verified programs run inside the Linux kernel without changing...
Writing Falco Rules with Macros, Lists, and Exceptions
Anatomy of a Falco rule A Falco rule says: when this condition is true, raise an alert with this message at this priority.
Tuning Falco to Cut Noise
Measuring alert volume before changing anything A new Falco install is noisy, and a noisy tool gets muted.
Mapping Detections to MITRE ATT&CK
What ATT&CK gives a detection engineer MITRE ATT&CK is a public catalogue of what real attackers do, grouped into tactics (the goal, such as...
Testing That Detections Actually Fire
Why untested rules fail silently A detection can fail without an error.
Skills You'll Master
Curriculum Index12 topics
Understanding Why Runtime Detection Is Needed
A clean image exploited at runtime The payment-service image at acme-shop passed every check.
Understanding eBPF in Plain Terms
What eBPF is and what it can see eBPF (extended Berkeley Packet Filter) lets small, verified programs run inside the...
Writing Falco Rules with Macros, Lists, and Exceptions
Anatomy of a Falco rule A Falco rule says: when this condition is true, raise an alert with this message at this...
Tuning Falco to Cut Noise
Measuring alert volume before changing anything A new Falco install is noisy, and a noisy tool gets muted.
Mapping Detections to MITRE ATT&CK
What ATT&CK gives a detection engineer MITRE ATT&CK is a public catalogue of what real attackers do, grouped into...
Testing That Detections Actually Fire
Why untested rules fail silently A detection can fail without an error.
Sharing Detections with Sigma
What Sigma is for Sigma is an open, vendor-neutral format for detection rules over logs.
Enforcing at Runtime with Tetragon and Watching Hosts with auditd
Detection versus enforcement Falco tells you something happened.
Centralising Security Logs and Tracking Findings to Remediation
Which sources to ship and where One alert in one place is a clue. The same alert next to cloud audit logs is a story.
Routing Alerts and Automating Response Safely
Alerting tiers: who gets woken up If everything pages someone, nothing does.
Hands-on Lab: Detect, Test, and Quarantine on kind
Before you start 📌 Remember: Cost: this lab runs entirely on your laptop and costs nothing.
Quick Reference and Common Mistakes
Quick reference Common mistakes Never testing the rules is the most common failure.
Career Impact
Roles that use the skills in this module.
- High Demand
DevSecOps Engineer
₹12L - ₹30L a year
- Growing
Detection Engineer
₹15L - ₹35L a year
- Growing
Security Operations Engineer
₹12L - ₹28L a year
Next Modules
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
Falco watches system calls and Kubernetes events, matches them against rules, and raises alerts. Tetragon also observes with eBPF but can enforce, killing a process or denying an action inside the kernel. Many teams run Falco for detection and add Tetragon only for a few high-confidence blocks.
Scans only find known problems in what you shipped. They cannot see a stolen token, a new vulnerability, or an attacker running commands in a healthy container. Runtime detection watches behaviour while the workload runs.
Measure which rules fire most, then add exceptions for known-good behaviour instead of disabling rules. Route alerts by priority so only urgent ones page someone, and review the rest weekly.
Not by default. Automatic actions should be reversible, such as relabelling a pod to isolate it and saving evidence. Deleting a pod destroys evidence and can hide the attack, so a human should approve it.