logo

Up and running with Stratoshark in 5 minutes

ID: c896b9cc-9609-559e-bc25-b073145c42e1

STIX ID: report--c896b9cc-9609-559e-bc25-b073145c42e1

Feed Name: Sysdig Blog

Date Published: 2025-05-12

Date Updated: 2026-05-01

...
...

This guide introduces Stratoshark—built by Wireshark’s founder and Falco’s creator—as a free, open-source tool that brings Wireshark-like investigative workflows to system calls and cloud logs. It covers installation on macOS/Windows, setting up remote syscall capture via sshdig with sysdig on a Linux host, and demonstrates an investigation by simulating an xmrig cryptominer in a container to show filtering, event context, and process ancestry for forensics. The piece is a tooling tutorial aimed at accelerating incident response and cloud-native investigations rather than a specific threat or incident report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.