DevSecOps Practitioner: Runtime Threat Detection & Response

placeholder

Even the most secure workloads can face unexpected threats in production. This course explores runtime security strategies for containers, virtual machines, and serverless functions. Learners will monitor system behavior, detect anomalies, and respond to incidents in real time to maintain continuous protection and resilience in cloud-native environments.In this course, explore how to instrument the kernel using eBPF to capture and analyze runtime activity for potential security anomalies. Next, discover how to craft Falco rules to detect and alert on suspicious behaviors across workloads, and integrate findings with SIEM or XDR platforms for centralized visibility. Finally, learn to execute incident-response playbooks that contain and mitigate attacks before they spread, ensuring production systems remain secure.After completing the course, you will be equipped to detect, investigate, and respond to runtime security threats using eBPF and Falco, integrate findings with SIEM or XDR systems, apply incident-response playbooks effectively, and maintain secure, compliant, and resilient cloud-native workloads in production environments.