-

Falco Threat Detection Extends to gVisor to Monitor Highly Sensitive Workloads

gVisor users can now run Falco for increased security and alerting of container workloads

SAN FRANCISCO--(BUSINESS WIRE)--Sysdig, the unified container and cloud security leader, today announced that open source Falco threat detection is the first security tool to monitor gVisor. gVisor, the container security platform developed by Google and open sourced in 2018, provides an additional layer of isolation between running applications and the host operating system.

While gVisor hardens applications with strict kernel isolation, the additional isolation could result in tools being unable to monitor for security events. The new Falco-gVisor integration solves this problem, enabling users to collect and analyze security events from gVisor. gVisor and Falco users, such as Mercari, can now enjoy the dual protection of container sandboxing and threat detection for their workloads.

“gVisor provides secure isolation between the container applications and the host operating system. This prevented us from monitoring gVisor with Falco, which uses host kernel system calls as a data source,” said Hiroki Suezawa, Senior Security Engineer at Mercari Inc. “Mercari has been using Falco for threat detection and container activity logging and has seen the power and flexibility of Falco’s rules engine. The collaboration between gVisor and Falco teams allows us to simultaneously use the enhanced isolation in gVisor, and threat detection and container activity audit in Falco. This drastically improves container security.”

Falco, an open source tool for continuous risk and threat detection across Kubernetes, containers, and cloud, monitors runtime system calls against set rules to trigger security alerts. Created by Sysdig and contributed to the CNCF in 2018, Falco now has more than 45 million downloads and contributions from a broad base of organizations. Falco detects unexpected behavior, configuration changes, intrusions, and data theft in real time.

What the Falco-gVisor integration means for users

The Falco-gVisor integration means that gVisor users now only need to instrument each host for monitoring, rather than every application, enabling Falco to monitor both containers and nodes. It was developed with the Falco open source community, based on engineering contributions from Sysdig and the gVisor team at Google.

Unifying the strong isolation capabilities of gVisor with the deep visibility of Falco enables users to detect anomalous behaviors within their workloads, adding syscall monitoring to the container sandbox that gVisor offers.

“The Falco-gVisor interface is great for any gVisor user looking for a multi-layer defense. gVisor's runtime monitoring infrastructure allows Falco to see what's happening inside the gVisor sandbox without the user having to do anything different. The integration is seamless as the same rules and configurations apply equally to containers running with gVisor," said Fabricio Voznika, Staff Software Engineer at Google.

"Today's security threats come from many directions. Falco and gVisor are a great combination, reducing the system surface exposed to containers, and providing visibility into what's happening at the workload level," said Edd Wilder-James, Vice President of Open Source Ecosystem at Sysdig. "Container-based architectures make Falco indispensable, and we're excited this capability is now available to gVisor users."

Resources

About Sysdig

Sysdig is driving the standard for cloud and container security. The company pioneered cloud-native runtime threat detection and response through creating Falco and Sysdig-oss as open source standards and key building blocks of the Sysdig platform. With the platform, teams can find and prioritize software vulnerabilities, detect and respond to threats, and manage cloud configurations, permissions, and compliance. From containers and Kubernetes to cloud services, teams get a single view of risk from source to run, with no blind spots, no guesswork, no black boxes. The largest and most innovative companies around the world rely on Sysdig.

Contacts

Media contact
Amanda McKinney Smith
amanda.smith@sysdig.com
703-473-4051

Sysdig


Release Summary
Open source Falco is the first security tool to monitor gVisor. Joint users can enjoy dual protection of container sandboxing and threat detection.
Release Versions

Contacts

Media contact
Amanda McKinney Smith
amanda.smith@sysdig.com
703-473-4051

Social Media Profiles
More News From Sysdig

Sysdig Launches Runtime Security for AI Coding Agents

SAN FRANCISCO--(BUSINESS WIRE)--RSA Conference 2026 – Sysdig, the leader in real-time AI-powered cloud defense, today announced runtime security for AI coding agents, enabling organizations to safely adopt autonomous development tools. As enterprises rapidly deploy coding assistants such as Claude Code, Codex, and Gemini, Sysdig provides the real-time visibility that organizations need to monitor agent behavior and identify risky activity across cloud and development environments. Enterprises a...

Sysdig Celebrates 10 Years of Falco with $70,000 Donation

AMSTERDAM--(BUSINESS WIRE)--KubeCon + CloudNativeCon Europe 2026 – Sysdig, the leader in real-time AI-powered cloud defense, today announced a $70,000 donation to the Falco project through the Linux Foundation’s crowdfunding initiative. The donation comes as Falco celebrates its 10th anniversary this year, and on the heels of a Cloud Native Computing Foundation (CNCF) survey reporting that 82% of AI workloads are now built on Kubernetes, up from 54% just one year earlier. Sysdig’s contribution...

Sysdig Named a Leader in CNAPP as Runtime Redefines Cloud Security in 2026

SAN FRANCISCO--(BUSINESS WIRE)--Sysdig today announced that it has been named a Leader in “The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026” report, earning the distinction alongside just two other companies. Out of 14 vendors evaluated, Sysdig was also one of only three cloud security providers rated above average for customer feedback, which Sysdig sees as a reflection of strong customer trust as organizations continue to realize increasing value from Sysdig’s runti...
Back to Newsroom