Skip to main content

Runtime Security and Detection Engineering

Learn to detect attacks in running containers with Falco, map detections to MITRE ATT&CK, test them, and route alerts to a safe, automated response.

~3.5 hours
12 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why Runtime Detection Is Needed

A clean image exploited at runtime The payment-service image at acme-shop passed every check.

Understanding eBPF in Plain Terms

What eBPF is and what it can see eBPF (extended Berkeley Packet Filter) lets small, verified programs run inside the Linux kernel without changing...

Writing Falco Rules with Macros, Lists, and Exceptions

Anatomy of a Falco rule A Falco rule says: when this condition is true, raise an alert with this message at this priority.

Tuning Falco to Cut Noise

Measuring alert volume before changing anything A new Falco install is noisy, and a noisy tool gets muted.

Mapping Detections to MITRE ATT&CK

What ATT&CK gives a detection engineer MITRE ATT&CK is a public catalogue of what real attackers do, grouped into tactics (the goal, such as...

Testing That Detections Actually Fire

Why untested rules fail silently A detection can fail without an error.

Skills You'll Master

RUNTIME-SECURITYFALCODETECTION-ENGINEERINGMITRE-ATTACKEBPF

Curriculum Index12 topics

1

Understanding Why Runtime Detection Is Needed

A clean image exploited at runtime The payment-service image at acme-shop passed every check.

2

Understanding eBPF in Plain Terms

What eBPF is and what it can see eBPF (extended Berkeley Packet Filter) lets small, verified programs run inside the...

3

Writing Falco Rules with Macros, Lists, and Exceptions

Anatomy of a Falco rule A Falco rule says: when this condition is true, raise an alert with this message at this...

4

Tuning Falco to Cut Noise

Measuring alert volume before changing anything A new Falco install is noisy, and a noisy tool gets muted.

5

Mapping Detections to MITRE ATT&CK

What ATT&CK gives a detection engineer MITRE ATT&CK is a public catalogue of what real attackers do, grouped into...

6

Testing That Detections Actually Fire

Why untested rules fail silently A detection can fail without an error.

7

Sharing Detections with Sigma

What Sigma is for Sigma is an open, vendor-neutral format for detection rules over logs.

8

Enforcing at Runtime with Tetragon and Watching Hosts with auditd

Detection versus enforcement Falco tells you something happened.

9

Centralising Security Logs and Tracking Findings to Remediation

Which sources to ship and where One alert in one place is a clue. The same alert next to cloud audit logs is a story.

10

Routing Alerts and Automating Response Safely

Alerting tiers: who gets woken up If everything pages someone, nothing does.

11

Hands-on Lab: Detect, Test, and Quarantine on kind

Before you start 📌 Remember: Cost: this lab runs entirely on your laptop and costs nothing.

12

Quick Reference and Common Mistakes

Quick reference Common mistakes Never testing the rules is the most common failure.

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

    ₹12L - ₹30L a year

    High Demand
  • Detection Engineer

    ₹15L - ₹35L a year

    Growing
  • Security Operations Engineer

    ₹12L - ₹28L a year

    Growing
See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

Falco watches system calls and Kubernetes events, matches them against rules, and raises alerts. Tetragon also observes with eBPF but can enforce, killing a process or denying an action inside the kernel. Many teams run Falco for detection and add Tetragon only for a few high-confidence blocks.

Scans only find known problems in what you shipped. They cannot see a stolen token, a new vulnerability, or an attacker running commands in a healthy container. Runtime detection watches behaviour while the workload runs.

Measure which rules fire most, then add exceptions for known-good behaviour instead of disabling rules. Route alerts by priority so only urgent ones page someone, and review the rest weekly.

Not by default. Automatic actions should be reversible, such as relabelling a pod to isolate it and saving evidence. Deleting a pod destroys evidence and can hide the attack, so a human should approve it.