Introduction to Falco
Workshop

A Falco pod in Running state does not prove that relevant runtime events are captured completely, reported clearly, and delivered reliably. Unverified default rules can quickly create noise, while broad exceptions leave blind spots. In this Falco training, you build more than an installation: you establish a traceable detection process. The workshop is designed for Kubernetes administrators, platform engineers, SREs, and security engineers with practical cluster and Linux experience. You use Falco as a runtime detection tool and distinguish its role from image scanning, admission control, hard

Made in Germany ISO 27001 ISO 9001 DSGVO-konform DORA Compliant 24/7 Support
UDSVolkswagenLiebherrT-SystemsVendureecoConnextPortainerBITMARCKUelzener VersicherungenFJDDWTOCCReiner SCTCyrus IndustrialDGSIEMnanocosmosInheadenSplixSchwarzgruppeINHHadesHiOrg-Serverown3dTikfinityProgram51Buben & MädchenPrime InsightsTELTECElevantiqMoovitCFToolsStadt KölnVivavisAvemio

Workshop overview

Duration, per-participant price and logistics for Introduction to Falco.

On-site options

  • Live online or on-site at your location

  • In-house: content, duration and focus can be tailored

  • Flexible dates, from 1 participant

  • German; English on request

  • Preconfigured cloud lab (also on-site)

  • Open groups: max. 8 people

  • Seat price same as online: €721.50 × days, excl. VAT

  • On-site in-house: individual quote (travel/logistics as incurred)

  • No published flat on-site surcharge

  • You provide the training room and internet

  • Open sessions: 09:00–16:00 (CET/CEST)

Curriculum

Topics by day at a glance.

Day 1: Position Falco, deploy it in the cluster, and verify runtime events

  • Position Falco in Runtime Security
  • Understand Event Sources and Drivers
  • Plan Installation for Kubernetes
  • Deploy and Verify Falco in the Cluster
  • Generate Controlled Runtime Events
Day 1

Day 2: Translate detection goals into reliable Falco rules and exceptions

  • Inspect Events, Fields, and Conditions
  • Structure Rules, Macros, and Lists
  • Test Rules Reproducibly
  • Adapt Default Rules Deliberately
  • Reduce False Positives with Exceptions
Day 2

Day 3: Route alerts, operate Falco, and handle a runtime incident

  • Produce Context-Rich Alerts
  • Connect Falcosidekick to a Test Destination
  • Verify Operational Metrics and Data Quality
  • Diagnose Event Drops and Routing Failures
  • Handle a Runtime Incident End to End
Day 3

Workshop schedule

Published daily rhythm. Topics are listed in the curriculum.

09:00–16:00 (CET/CEST)

Official window for open sessions.

Frame

09:00 – Introductions

On day 1: meet the instructor and participants, plus the agenda and workshop structure.

Day 1

09:00 – Q&A

On later days, resolve open questions from the previous day before the day’s topics (usually 09:00–09:30 or 09:00–10:00).

Later days

Content blocks follow the curriculum

Theory and hands-on in the morning and afternoon blocks. The topic list is in the curriculum above.

Topics

12:00–13:00 – Lunch

A shared break before the afternoon.

Break

16:00–16:30 – Q&A

End of the day: questions, exchange and wrap-up.

Close

Prerequisites

What participants should bring.

Hardware

Your own notebook (Linux, macOS or Windows) with permission to install software. Devices available at extra cost.

HardwareNotebook

Environment

Each participant works in a provided cloud lab. Local installation of the training stack is not required.

LabCloud

Prerequisites

Basic Linux/terminal skills are helpful.

Prerequisites

Related workshops

Suggested follow-on courses from the catalog.

Kubernetes Monitoring

  • Duration: 4 days