What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
- Current module names and packaging: confirm against vendor documentation
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Sysdig Secure is built on the same syscall instrumentation that underlies Falco, which Sysdig originated and contributed to the CNCF. An agent on each node collects kernel events through eBPF, enriches them with container and Kubernetes metadata, and evaluates them against managed and custom Falco rules. The commercial platform adds the operational layer around that engine: a maintained rule feed, policy management across clusters, alert routing, and response actions such as killing an offending container.
The forensics capability is the part that is hard to replicate elsewhere. Because the agent already has the syscall stream, Sysdig can capture a window of activity around a detection and let an analyst replay exactly what the process did after the container is gone. That answers the recurring problem in container incident response: the evidence normally disappears with the workload. The platform also covers image and host vulnerability scanning, using runtime usage data to prioritize packages actually loaded, plus cloud posture, CIEM and infrastructure as code scanning.
Where it fits
This is a production control operated by security operations, with platform engineering handling agent deployment across clusters and hosts. Agents run as a DaemonSet, cloud accounts connect through roles, and IaC scanning attaches to repositories. Two prerequisites are real: node kernels must support the instrumentation method you choose, and you need an alert triage process, because runtime detection generates findings that require human investigation.
Strengths
- Deep kernel-level visibility, so detection does not depend on what the application chooses to log.
- Syscall capture and replay gives genuine post-incident forensics for workloads that no longer exist.
- Runtime usage data applied to vulnerability findings cuts the prioritization problem down substantially compared to scanning images in isolation.
- Falco compatibility means custom detections are portable and the rule language is publicly documented.
Limitations
- Agent-based by design, so coverage is bounded by where the agent is deployed, and restricted node environments complicate that.
- Syscall collection on busy nodes has measurable resource overhead, and capture retention adds storage requirements of its own.
- Runtime detection needs ongoing tuning, and the initial period generates noise from legitimate but unusual application behavior.
- The Falco core is available separately, so teams able to run and tune it themselves may find the platform's value concentrated in the surrounding workflow rather than the detection engine.
Who it suits
Right for organizations running containers in production at a scale where runtime compromise matters and there is a security operations team to receive and investigate alerts. Not the right first purchase for a team whose gap is misconfigured infrastructure code or unpatched images, where simpler controls cover more ground.
Used Sysdig Secure? Recommend it under your own name and title.
Recommend this tool