KubeSentry
Kernel-level runtime threat detection for Kubernetes clusters built on Falco and eBPF to detect reverse shells, crypto miners, privilege escalation and lateral movement
The product is kernel-level runtime threat detection for Kubernetes clusters that identifies threats such as reverse shells, crypto miners, privilege escalation and lateral movement. It is for DevOps and SRE teams, IT teams and developers in businesses that operate Kubernetes workloads. It is delivered as a self-hosted Helm chart built on Falco and eBPF that runs entirely inside the customer's own cluster with no phone-home or telemetry and sends alerts only to destinations the customer configures.
Key features
- Kernel-level runtime threat detection
- eBPF-based detection via Falco
- One-command Helm chart install
- Self-hosted in own cluster
- Curated detection rules
- Reverse shell detection
- Crypto miner detection
- Privileged container detection
- Sensitive file access detection
- RBAC role modification detection
- Slack instant alerts
- Email digest alerts
- Discord and Teams alerts
- Custom webhook alerts
- Triage steps and remediation commands
- MITRE ATT&CK references
- Alert dashboard with filtering
- No social media activity within the last 30 days
GTM channels
- Docs
ICP
- DevOps sre teams
- Security teams
- IT teams