logo

Open source spotlight: Bringing web application security to Falco with Falcoya's Nginx plugin

ID: 3cfaf355-3b05-5e32-abdc-3ecd3436988d

STIX ID: report--3cfaf355-3b05-5e32-abdc-3ecd3436988d

Feed Name: Sysdig Blog

Date Published: 2025-10-02

Date Updated: 2026-05-01

...
...

This document introduces Falcoya (falco-plugin-nginx), an open-source plugin that extends Falco’s runtime security to the web layer by parsing Nginx access logs and applying Falco-style YAML rules to detect application-layer attacks (e.g., SQLi, XSS, command injection, directory traversal) in real time. It emphasizes lightweight performance, easy custom rule creation, seamless integration with existing Falco deployments, and includes quick-start installation and testing commands to help teams gain web application visibility without relying on a separate WAF.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.