Falcovs
Sysdig


Sysdig: If you want the commercial platform from Falco’s creators, with storage, console, triage and response included rather than assembled

CNCF-graduated runtime threat detection for Linux and Kubernetes using eBPF
As of 31 August 2026, Falco is free to use. Open source runtime security that watches kernel system calls and alerts on suspicious behaviour inside running containers. Softwr lists it under Cybersecurity. Falco is made by Cloud Native Computing Foundation, project created by Sysdig, available on Linux, Kubernetes, Self-hosted.
Overview
Falco taps the Linux kernel through a modern eBPF probe, reconstructs the stream of system calls made by processes on the node, enriches them with container and Kubernetes metadata, and evaluates them against a rules engine. When a rule matches, a shell spawning inside a container, a write to a path under /etc, an outbound connection from a process that should never make one, it emits an event. It ships as a DaemonSet so every node is covered, runs on x86_64 and aarch64, and is licensed Apache 2.0. The governance fact matters here. Falco was created and open sourced by Sysdig in 2016, entered the CNCF sandbox in 2018 and graduated in February 2024, making it the first runtime security project to reach that level. Graduation means the project is not Sysdig’s to change unilaterally, which is a genuine reduction in vendor risk compared with an open-core tool whose maintainer can relicense it. Sysdig still sells the commercial platform most large Falco users end up buying alongside it. Buyers are platform and security teams running Kubernetes who need detection at the kernel layer that image scanning cannot provide. The trade-off is that Falco is one component of a detection capability, not the capability itself. It has no storage, no console, no case management and no response action. You supply Falcosidekick, an event store, alert routing, tuning and the people to read what comes out. Untuned, it is loud enough that teams stop reading it, which is the most common way a Falco deployment fails.
The honest half
Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Falco.
Cross-shopped
Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.


Sysdig: If you want the commercial platform from Falco’s creators, with storage, console, triage and response included rather than assembled


Wiz: If your priority is agentless cloud posture and risk prioritisation across accounts rather than per-node kernel detection


Snyk: If the risk you are actually managing is vulnerable dependencies and images before deployment rather than behaviour at runtime
Pricing
Taken from the vendor's own pricing page. Prices move, so check before you buy.
Falco (open source)
Free
Capabilities
eBPF kernel instrumentation
Modern CO-RE eBPF probe as default, with legacy eBPF and a kernel module for older kernels
System call rules engine
YAML rules matched against enriched syscall events
Container and Kubernetes context
Events tagged with pod, namespace, image and label metadata
Default rule set
Community-maintained rules for common container attack behaviour
Falcosidekick
Fan-out of events to Slack, webhooks, SIEMs, object storage and message queues
Falco Talon
Response engine for triggering actions on a rule match
Plugins framework
Extends detection beyond syscalls to sources such as cloud audit logs
DaemonSet deployment
Per-node coverage on x86_64 and aarch64 clusters
Apache 2.0 licence
CNCF-governed, no commercial licence tier in the project itself
Answered, with sources
Each answer names the page it came from, so you can check it rather than take our word for it.
No. It detects and emits events. Response requires Falco Talon or your own automation on top.
Sysdig created and open sourced it, but it graduated within the CNCF in February 2024, so governance sits with the foundation rather than the vendor.
The project is Apache 2.0 with no licence fee. The cost is the storage, routing, tuning and staff time needed to make its output useful.
Kernel 5.8 or later for the default modern eBPF driver. Older hosts need the legacy eBPF probe or the kernel module.
Keep looking
Certificate-based access to servers, Kubernetes, databases and apps, replacing shared credentials and VPNs
XDR platform correlating Trend Micro's endpoint, email, server, cloud and network sensors, licensed through a shared credit pool.
AI-driven endpoint protection and detection
Modern, minimal-complexity VPN protocol with state-of-the-art cryptography
Open-source static analysis tool for finding security bugs and enforcing code standards.
Quest-owned identity governance, PAM and Active Directory management
Free, open-source web application scanner and intercepting proxy, now governed by the Software Security Project.
Open-source password manager for teams with self-hosted or cloud deployment
Enterprise identity for workforce and customers, with a 5,000 user floor
Softwr does not host reviews and shows no star rating for Falco, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.
What people switch to, and what they give up
Every tier, and where the cost actually lands
Put it head to head with anything we hold
Its rating, and an embed for your own site
Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use
quoteManaged video loss prevention with human auditors for restaurants, convenience stores and retail
quoteWorkforce and customer authentication from a certificate authority
Per user per monthPrivileged access management, endpoint privilege management and secure remote access
quoteCloud video surveillance billed per camera per month, where retention length drives the bill more than anything else
Per camera per monthAI video search that runs on cameras you already own, starting near five dollars per camera per month
Per camera per monthPhishing-resistant passwordless authentication with device trust enforced at every login
quote