Introduction to Falco
Duration: 3 days (09:00 – 16:00 CET/CEST)
Participants: Max. 8 people
Format: Online or on-site
Language: German (English on request)
Certificate: ayedo certificate of attendance
Introduction to Falco
Workshop
A Falco pod in Running state does not prove that relevant runtime events are captured completely, reported clearly, and delivered reliably. Unverified default rules can quickly create noise, while broad exceptions leave blind spots. In this Falco training, you build more than an installation: you establish a traceable detection process. The workshop is designed for Kubernetes administrators, platform engineers, SREs, and security engineers with practical cluster and Linux experience. You use Falco as a runtime detection tool and distinguish its role from image scanning, admission control, hard































Workshop overview
Duration, per-participant price and logistics for Introduction to Falco.
Introduction to Falco
Duration: 3 days (09:00 – 16:00 CET/CEST)
Participants: Max. 8 people
Format: Online or on-site
Language: German (English on request)
Certificate: ayedo certificate of attendance
On-site options
Live online or on-site at your location
In-house: content, duration and focus can be tailored
Flexible dates, from 1 participant
German; English on request
Preconfigured cloud lab (also on-site)
Open groups: max. 8 people
Seat price same as online: €721.50 × days, excl. VAT
On-site in-house: individual quote (travel/logistics as incurred)
No published flat on-site surcharge
You provide the training room and internet
Open sessions: 09:00–16:00 (CET/CEST)
Curriculum
Topics by day at a glance.
Day 1: Position Falco, deploy it in the cluster, and verify runtime events
Day 2: Translate detection goals into reliable Falco rules and exceptions
Day 3: Route alerts, operate Falco, and handle a runtime incident
Workshop schedule
Published daily rhythm. Topics are listed in the curriculum.
09:00–16:00 (CET/CEST)
Official window for open sessions.
09:00 – Introductions
On day 1: meet the instructor and participants, plus the agenda and workshop structure.
09:00 – Q&A
On later days, resolve open questions from the previous day before the day’s topics (usually 09:00–09:30 or 09:00–10:00).
Content blocks follow the curriculum
Theory and hands-on in the morning and afternoon blocks. The topic list is in the curriculum above.
12:00–13:00 – Lunch
A shared break before the afternoon.
16:00–16:30 – Q&A
End of the day: questions, exchange and wrap-up.
Prerequisites
What participants should bring.
Hardware
Your own notebook (Linux, macOS or Windows) with permission to install software. Devices available at extra cost.
Environment
Each participant works in a provided cloud lab. Local installation of the training stack is not required.
Prerequisites
Basic Linux/terminal skills are helpful.
Related workshops
Suggested follow-on courses from the catalog.
CKS Preparation
Duration: 4 days
Kubernetes Monitoring
Duration: 4 days