falcosecurity/falco
Cloud Native Runtime Security
About the project
Falco is a cloud native runtime security tool for Linux that monitors syscalls and container/Kubernetes events against custom rules, alerting on abnormal behavior in real time.
Useful for
- Set up alerts for suspicious syscalls in a Kubernetes cluster
- Forward Falco events to a SIEM or data lake for analysis
- Run the docker-compose demo environment with Falco and its UI
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 1 star so far today, about 3 expected by the end of the day.
- GitHub Trending C++ today: #9, +6 stars.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 9,404
- Today
- 1 · ≈ 3 by evening
- Forks
- 1,080
- Issues and pull requests
- 3,914
- Watchers
- 131
- Language
- C++
- License
- Apache-2.0
- Latest release
- 0.45.0 · September 21, 2026
- Created
- January 19, 2016
- Last push
- September 21, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 22, 2026GitHub Trending C++ today: #9, +6 stars
More in this category
-
6.5
mvt-project/mvt
A collection of mobile forensics utilities that gather and analyze traces of compromise on Android and iOS devices, matching them against public indicators of compromise (IOCs). Built by Amnesty International Security…
-
6.0
newliver666/apk-reverse
An Agent Skill for Android APK reverse engineering: unpacking, ad removal, dex patching, repacking, and runtime/server analysis. Loaded by an agent (Claude Code, Codex) while it works.
-
5.2
cloudflare/security-audit-skill
A coding-agent skill that turns the agent into a security auditor, running a multi-phase code audit with independently verified, machine-readable findings.
-
3.9
MSNightmare/BigDiskBuster
A C++ proof-of-concept that blocks Windows Defender platform and signature updates, causing a denial of service for the antivirus.
-
3.6
ejfkdev/ddc
A Rust DEX-to-Java decompiler for Android with progressive analysis: query metadata first and decompile classes on demand instead of a full run. Its output is javac-verified across seven real-world APKs.
-
3.5
calesthio/Crucix
A local OSINT terminal that aggregates 27 open-source feeds (satellites, radiation, flights, markets, conflicts, social) into a single Jarvis-style dashboard with a 3D globe, refreshing every 15 minutes.