CAPABILITIES
What it provides
- Supported execution, file, and connection events such as execve, openat, and connect.
- Process and parent context, user attributes, and available event details.
- Detection rules that suppress, escalate, downgrade, or tag events.
- Monitor, alert, simulation, and supported enforcement modes with container enrichment.
DEPLOYMENT WORKFLOW
How to use it
- 01
Deploy and connect a compatible Linux host agent, then verify active tracing programs.
- 02
Review Runtime Security events and tune detection rules for expected workload behavior.
- 03
Validate the effect of host enforcement policies in monitoring or simulation before enabling a disruptive response.
CONFIGURATION & OPERATION
Where it fits in your setup
Use Runtime Security for event investigation and rule configuration. Docker/containerd integration enriches events when the runtime socket is available; missing enrichment does not turn every event into a container-attributed event.
COVERAGE & LIMITS
What to account for
Coverage depends on attached probes, kernel capabilities, and trace configuration. Supported enforcement mechanisms may terminate matching processes; they are not a universal guarantee that every syscall is blocked before execution.