Updated About Falco (markdown)

Mark Stemm
2016-12-21 15:13:36 -08:00
parent f0601604e2
commit f463df9cf9

@@ -11,6 +11,10 @@ Falco can detect and alert on any behavior that involves making Linux system cal
- A non-device file is written to `/dev`
- A standard system binary (like `ls`) makes an outbound network connection
## How Falco Compares to Other Security Tools like SELinux, Auditd, etc.
One of the questions we often get when we talk about Sysdig Falco is “How does it compare to other tools like SELinux, AppArmor, Auditd, etc. that also have security policies?”. We wrote a [blog post](https://sysdig.com/blog/selinux-seccomp-falco-technical-discussion/) comparing Falco to other tools.
## How you use it
Falco is deployed as a long-running daemon. You can install it as a debian/rpm