Falco

Open-source runtime security project (CNCF) that detects suspicious behavior in containers and hosts. Uses kernel-level events to create real-time policies and alerts.