Falco, by the risk it changes
A runtime monitoring agent that watches kernel events and alerts on rules. Written as an answer, some of what the agent did on its host can be read back, for the events the rules match.
A runtime monitoring agent that watches kernel events and alerts on rules. Written as an answer, some of what the agent did on its host can be read back, for the events the rules match.
The model asks sixteen questions about an agent deployment. A product’s effect is written as the answers it changes, and each change says what kind of change it is: a statement of what is true, an expectation the agent is asked to meet, a setting, or a boundary enforced by something the agent’s grant does not include.
Computed from the model for the deployment above: every risk that holds without it, and every risk that holds with it. A new entry is either one the change brought to light, where an answer replaced a don’t know, or a narrower risk in place of a wider one, where the answer moved from no to partly. Either way the register is more exact, and a register that grows because something was found is working.
Retired
New
Each risk is assigned to the roles it belongs to, and each role reports to another until the board. The count beside each role is the entries it holds without the product and with it.
At the board: the corporate register
Corporate risks have no facts of their own. They hold while any risk that leads into them holds, so a single product rarely retires one. What it changes is how many reasons the board is being given.
It runs with deep access to the host kernel. Its troubleshooting page describes busy servers on which it may drop events.
An open-source project costs nothing to download and something to adopt. Every change above depends on the work below, and most of it is customisation to your own deployment.
Each pair was read on the same day. We have not tested which is true, because that would mean testing somebody else’s system.
Next. Published, and sent to the project's maintainers at the same time. If a change is wrong, or another answer should move, the case changes with the date they said so.
If you build a security product for agents, the case for it can be written the same way: what it does in your own words, the answers it changes, and the register before and after. If a case here is wrong about you, tell us and it changes with a date.