Falco 0.10.0 released.
Blog post from Sysdig
Falco 0.10.0 introduces several enhancements aimed at simplifying deployment, refining rules, and expanding system call support. The update allows users to specify a rules directory for organized rule loading and includes a sample Puppet Module for easier configuration management. New rules have been added, such as those detecting unauthorized SSH connections and unexpected Kubernetes NodePort interactions, while existing rules have been refined to reduce false positives. Support for syscalls has been expanded to include all those supported by Sysdig, with options for users to manage syscall availability. Other improvements include log rotation support, compact JSON output, and fixes for rule validation and order issues. The release is available through various channels, and further details can be found in the GitHub changelog.