Leonardo Grasso
Falco Core Maintainer
Giarre, Italy
Actions
Leonardo Grasso is an Open Source Software Engineer at Sysdig, based in Italy. He has a strong passion for software design and has long professional experience in the R&D field. Leonardo loves Linux, Kubernetes, Containers, Security, and building tools other engineers would like to use. Currently, he primarily takes care of Falco, a Container Native Runtime security project hosted by the CNCF, and he is a core maintainer of the project.
Links
Area of Expertise
When Falco Spots Trouble, the Shark Swims In
What if Falco could not only detect suspicious activity, but also capture the system call trail behind it? Enter StratoShark—a powerful new integration that lets Falco trigger targeted runtime captures for deep, Wireshark-style analysis. In this lightning-fast talk, Gerald will show how Falco and StratoShark work together to bridge detection and investigation, giving you forensic-level visibility when and where it matters most.
In Falco's Nest: The Evolution of Cloud Native Runtime Security
Falco, the Cloud Native Runtime Security project, is constantly evolving to meet the demands of modern cloud environments. This maintainer track session, led by the Falco maintainers, will dive deep into the latest advancements and the strategic direction of the project. We will focus on two major areas of growth: the introduction of the new Falco Operator and the new features that enhance Falco's performance and reliability.
The new Falco Operator simplifies the deployment, configuration, and management of Falco across Kubernetes clusters, making it easier than ever for users to secure their runtime environments at scale.
Furthermore, we will explore the most significant new features integrated into Falco. This includes performance optimizations for high-throughput environments. The session will also touch upon community contributions, ecosystem integrations, and the roadmap for the upcoming release.
Falco Never Flies Alone: Runtime Security as an Ecosystem
Falco has never flown alone. Around the runtime security engine at its core, a whole ecosystem has taken shape: the Operator that runs it, the connectors that carry its events, and the projects that turn detections into action. In this maintainer track session, the maintainers will look at how that ecosystem is maturing and where the project is heading next.
We will share the most relevant developments in Falco itself, from detection and performance to a smoother experience for writing and maintaining rules, and give particular attention to the ecosystem growing around it. With the Operator now production-ready, deploying and managing Falco across Kubernetes clusters is simpler than ever, and the projects around it keep expanding what teams can do once an event leaves the engine.
Join the maintainers for a look at what has changed since we last met, an honest view of where the project stands today, and a preview of the directions we are most excited about for the releases ahead.
Forensics with Falco
Falco has recently expanded its capabilities with capture recording, opening the door to seamless integration with forensic analysis tools like Stratoshark. In this lightning talk, Gerald will walk through how the two tools work together to provide deep visibility into container and system activity. He will demonstrate how captured event data can accelerate investigations and discuss key considerations for safely and efficiently deploying these features in production environments.
Falco Never Flies Alone: Runtime Security as an Ecosystem
Falco has never flown alone. Around the runtime security engine at its core, a whole ecosystem has taken shape: the Operator that runs it, the connectors that carry its events, and the projects that turn detections into action. In this maintainer track session, the maintainers will look at how that ecosystem is maturing and where the project is heading next.
We will share the most relevant developments in Falco itself, from detection and performance to a smoother experience for writing and maintaining rules, and give particular attention to the ecosystem growing around it. With the Operator now production-ready, deploying and managing Falco across Kubernetes clusters is simpler than ever, and the projects around it keep expanding what teams can do once an event leaves the engine.
Join the maintainers for a look at what has changed since we last met, an honest view of where the project stands today, and a preview of the directions we are most excited about for the releases ahead.
Beyond the Cloud(s): Falco’s Ascent in Performance and Deep Visibility
Falco is soaring higher than ever into the stratosphere of observability—faster, sharper, and with a deeper lens into cloud native runtime security. In this session, maintainers will reveal two major breakthroughs: a reengineered event collection strategy that delivers significant performance gains, and a pioneering integration with StratoShark that enables Falco to capture targeted runtime activity for powerful post-incident analysis. These innovations push Falco beyond traditional detection into a new realm of forensic depth and responsiveness. Join us for a glimpse of what’s next as Falco charts a course toward faster, wiser, and more connected runtime security.
Avoid an ill Wind and Catch the Jet Stream – Using Falco To Detect Attackers & Compliance Violations
As a widely embraced cloud native runtime security tool, Falco is a reliable and effective real-time threat detection and compliance violation monitoring project essential for your needs in today’s dynamic environments. Get wind of happenings in your diverse infrastructure through Falco’s new rules maturity framework; designed to ease your onboarding experience with Falco detections and accompanied by contribution, tuning, and style guides. With improved performance tailored specifically for our expanding pool of adopters, Falco now includes greater configurability, innovations with plugins, and so much more. These changes propel your organization forward and position you to power-dive into events and calls for when your workloads start going south — with a simple Falco setup you can elevate your threat response team to new heights with cloud native insights.
Peak Innovation and Cloud Tweaks: Falco’s Ongoing Runtime Security Development
In the fast-paced world of cloud-native runtime security, Falco embraces innovation and adaptability. As a trusted CNCF-graduated project, Falco keeps evolving to meet today’s security challenges with new approaches. This session covers Falco’s latest developments, including better rule handling for flexible ruleset customization and output definition, integration with Prometheus metrics, and an improved installation experience. We will also look at new language extensions and operators, improvements in performance and testing, and powerful new plugins for advanced data modeling. Join us in celebrating Falco’s ongoing efforts to refining runtime security and its dedication to the future of cloud-native environments.
Falco: A Grand Promenade Through Cloud Native Runtime Security
In the bustling world of cloud-native runtime security, Falco is a reliable and effective real-time threat detection and compliance violation monitoring project and stands as an unwavering companion for your needs. Journey through Falco’s remarkable transformation, from its incubation days to its current standing as a CNCF-graduated project, witnessing its pivotal milestones: adept threat detection, intuitive rule structuring, performance enhancements catering to a burgeoning community, an adaptable plugin framework, enhanced user-friendliness, and a robust governance structure ensuring sustained success. Continuing this trajectory, Falco remains dedicated to relentless advancement, continuously refining its capabilities to detect stealthy cyber threats. Join us in celebrating Falco’s legacy and embracing its promising future.
Maintainer Track + ContribFest: KubeCon + CloudNativeCon Europe 2024 Sessionize Event
KubeCon + CloudNativeCon North America 2023 Sessionize Event
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top