resources
 > Content library

Browse all content by asset type.

filter by:
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
No items found.

Blog Posts

Monitoring with Custom Metrics
Monitoring with Custom Metrics
Monitoring

Monitoring with Custom Metrics

Javier Martínez
|
March 1, 2023
SCARLETEEL: Operation leveraging Terraform, Kubernetes, and AWS for data theft
SCARLETEEL: Operation leveraging Terraform, Kubernetes, and AWS for data theft
Cloud Security
Threat Research

SCARLETEEL: Operation leveraging Terraform, Kubernetes, and AWS for data theft

Alberto Pellitteri
|
February 28, 2023
Aligning Falco’s Cloudtrail Rules with MITRE ATT&CK
Aligning Falco’s Cloudtrail Rules with MITRE ATT&CK
Cloud Security
Open Source

Aligning Falco’s Cloudtrail Rules with MITRE ATT&CK

Nigel Douglas
|
February 28, 2023

Briefs

Sysdig Corporate Brief
Sysdig Corporate Brief

Sysdig Corporate Brief

Founded by the creators of open source standards — Falco, Stratoshark, and Wireshark — and built on agentic AI, Sysdig delivers real-time cloud defense grounded in the uncompromising truth of runtime.

BRIEF. 2025 Cloud‐Native Security and Usage Report
BRIEF. 2025 Cloud‐Native Security and Usage Report

BRIEF. 2025 Cloud‐Native Security and Usage Report

This is a special edition of Sysdig’s 2025 Cloud-Native Security and Usage Report, providing only the usage and analysis of the open source detection tool, Falco.

BRIEF. Top 5 Best Practices For Image Scanning
BRIEF. Top 5 Best Practices For Image Scanning

BRIEF. Top 5 Best Practices For Image Scanning

How do you manage container security risk without slowing down application delivery?

Case Studies

Greater Stability, Smarter Planning: How a Global Enterprise Gained Control of Its Cloud

Greater Stability, Smarter Planning: How a Global Enterprise Gained Control of Its Cloud

Global Technology Leader unifies cloud monitoring to eliminate blind spots and outages

Caught in Runtime: How Sysdig Detected Credential Exposure in a Crypto Platform Before It Became a Breach

Caught in Runtime: How Sysdig Detected Credential Exposure in a Crypto Platform Before It Became a Breach

Cryptotrading Platform prevents breach with real-time visibility

Good-Enough Security Isn’t Good Enough When You Serve a Billion People

Good-Enough Security Isn’t Good Enough When You Serve a Billion People

UIDAI secures 1.4B+ identities and 100M daily authentications with Sysdig.

Ebooks

Top 6 Use Cases for Monitoring Cloud-Native Workloads with Sysdig Monitor
Top 6 Use Cases for Monitoring Cloud-Native Workloads with Sysdig Monitor

Top 6 Use Cases for Monitoring Cloud-Native Workloads with Sysdig Monitor

Securing the Cloud: The Benefits of Falco with an Enterprise Experience
Securing the Cloud: The Benefits of Falco with an Enterprise Experience

Securing the Cloud: The Benefits of Falco with an Enterprise Experience

An ebook with 3 mini case studies heavily featuring Falco and how it works with Sysdig, plus a callout to Falco Feeds at the end.

The Value of Sysdig's CNAPP
The Value of Sysdig's CNAPP

The Value of Sysdig's CNAPP

Guides

Cloud Security for Google Cloud
Cloud Security for Google Cloud

Cloud Security for Google Cloud

This guide outlines key requirements and capabilities for establishing comprehensive security for Google Cloud services and containers.

Cloud Security for Amazon Web Services
Cloud Security for Amazon Web Services

Cloud Security for Amazon Web Services

This guide outlines key requirements and capabilities for establishing comprehensive security for AWS cloud services and containers.

Secure Your Cloud in Minutes - Your Checklist for Meeting the 555 Benchmark
Secure Your Cloud in Minutes - Your Checklist for Meeting the 555 Benchmark

Secure Your Cloud in Minutes - Your Checklist for Meeting the 555 Benchmark

Sysdig’s 555 Benchmark for Cloud Detection and Response offers a standard to use when measuring how fast your security teams can counter attackers. Specifically, the benchmark finds that to outpace attacks, your security teams need to detect threats within 5 seconds, correlate and triage data within the first 5 minutes, and initiate a tactical response within the next 5 minutes.Sysdig’s 555 Benchmark for Cloud Detection and Response offers a standard to use when measuring how fast your security teams can counter attackers. Specifically, the benchmark finds that to outpace attacks, your security teams need to detect threats within 5 seconds, correlate and triage data within the first 5 minutes, and initiate a tactical response within the next 5 minutes.

Infographics

Unlock the Power of NIS2
Unlock the Power of NIS2

Unlock the Power of NIS2

The Evolution of Modern Cloud Security
The Evolution of Modern Cloud Security

The Evolution of Modern Cloud Security

Remember asking your teachers why you needed to know history? They probably said that learning history is important in understanding how society has changed and progressed over time, and that we can learn from past experiences and mistakes.

The Grand Atlas of Software Security
The Grand Atlas of Software Security

The Grand Atlas of Software Security

This infographic demonstrates how to secure each stage of the software lifecycle, with a focus on the Shift Left approach, where early remediation reduces risks and costs.

Podcasts

Exploring Advanced Cybersecurity with Michael Isbitski

Exploring Advanced Cybersecurity with Michael Isbitski

"Cybersecurity leader Mike Isbitski explores the intricacies of cloud-native security and vulnerability management in today's technological landscape. With over 25 years of experience, he provides valuable insights into the challenges and complexities organizations face in securing ephemeral infrastructure and machine identities in the cloud. This episode also explores the cautious adoption of AI in cybersecurity, emphasizing the need for a balanced approach that maintains operational functionality while addressing evolving security concerns."

Screaming in the Cloud: Benchmarking Security Attack Response Times in the Age of Automation with Anna Belak

Screaming in the Cloud: Benchmarking Security Attack Response Times in the Age of Automation with Anna Belak

"Anna Belak, Director of the Office of Cybersecurity Strategy at Sysdig, joins Corey on Screaming in the Cloud to discuss the newest benchmark for responding to security threats, 5/5/5. Anna describes why it was necessary to set a new benchmark for responding to security threats in a timely manner, and how the Sysdig team did research to determine the best practices for detecting, correlating, and responding to potential attacks. Corey and Anna discuss the importance of focusing on improving your own benchmarks towards a goal, as well as how prevention and threat detection are both essential parts of a solid security program."

Screaming in the Cloud: An Open-Source Mindset in Cloud Security with Alex Lawrence

Screaming in the Cloud: An Open-Source Mindset in Cloud Security with Alex Lawrence

"Alex Lawrence, Field CISO at Sysdig, joins Corey Quinn on Screaming in the Cloud to discuss how he went from studying bioluminescence and mycology to working in tech, and his stance on why open source is the future of cloud security."

Press Releases

Sysdig Expands the Power of Runtime Context with New MCP Server and Partner Integration Hub
Sysdig Expands the Power of Runtime Context with New MCP Server and Partner Integration Hub

Sysdig Expands the Power of Runtime Context with New MCP Server and Partner Integration Hub

Sysdig, the leader in real-time cloud security, today announced the launch of its Model Context Protocol (MCP) server and partner integration hub, giving customers access to AI-powered security insights across their entire ecosystem.

October 15, 2025
Sysdig Unveils the Industry’s First Agentic Cloud Security Platform
Sysdig Unveils the Industry’s First Agentic Cloud Security Platform

Sysdig Unveils the Industry’s First Agentic Cloud Security Platform

With semantic analysis powered by autonomous AI agents, Sysdig Sage™ surfaces critical business risks and helps organizations fix them at the source in minutes

August 5, 2025
Sysdig Launches Open Source Community to Unite and Empower Millions of Cloud Security Innovators and Builders of All Levels
Sysdig Launches Open Source Community to Unite and Empower Millions of Cloud Security Innovators and Builders of All Levels

Sysdig Launches Open Source Community to Unite and Empower Millions of Cloud Security Innovators and Builders of All Levels

The company’s new forum establishes a place where Falco, Wireshark, Stratoshark, and sysdig OSS users can connect, collaborate, and growSAN…

July 9, 2025

Reports

Latio Tech 2025 Cloud Security Market Report
Latio Tech 2025 Cloud Security Market Report

Latio Tech 2025 Cloud Security Market Report

The 2025 Latio Cloud Security Market Report examines the technologies and strategies shaping the next generation of cloud and AI defense. As organizations adopt AI workloads and distributed architectures, the traditional boundaries of security continue to dissolve. Latio’s analysis highlights how the market is shifting from visibility to real-time, runtime protection—and why this evolution is critical to managing machine-speed risk. Within the report, Latio names Sysdig a leader for its ability to deliver the depth of telemetry, customization, and AI-driven correlation security teams need to operationalize cloud incident-response programs. By combining open innovation with deep runtime visibility, Sysdig helps organizations detect, prioritize, and respond to threats faster—across hybrid and AI-powered environments. This report serves as the most comprehensive guide for security leaders looking to understand where the market is headed, what capabilities define the leaders, and how to prepare their organizations for the future of cloud and AI security.

2025 Cloud Defense Report
2025 Cloud Defense Report

2025 Cloud Defense Report

Cloud attacks are accelerating, vulnerabilities are multiplying, and AI is reshaping both the attack surface and expectations for defense. In 2025, security leaders face a defining paradox: embracing AI to innovate and protect, while defending against the very AI-powered threats that evolve in seconds. The future of security lies in real-time, context-aware defense—rooted in visibility, collaboration, and AI that empowers defenders to move as fast as attackers.

Sysdig 2024 Cloud-Native Security and Usage Report
Sysdig 2024 Cloud-Native Security and Usage Report

Sysdig 2024 Cloud-Native Security and Usage Report

Videos

Detecting Threats to Kubernetes, Containers, and Google Cloud

Detecting Threats to Kubernetes, Containers, and Google Cloud

See how Sysdig helps secure and accelerate innovation with Google Cloud.

Secure DevOps Practices at Yahoo Japan

Secure DevOps Practices at Yahoo Japan

With more than 3,000 developers and a large Kubernetes environment, learn how Yahoo Japan is preventing cyber-attacks and unauthorized access by introducing appropriate security measures for the container environment.

Securing and Monitoring AWS Container Services

Securing and Monitoring AWS Container Services

Developers, operations, and security teams must work together to address key workflows to secure and monitor containers, Kubernetes and cloud services across...

Webinars

Troubleshoot Kubernetes in A Snap with Sysdig Monitor Advisor
Troubleshoot Kubernetes in A Snap with Sysdig Monitor Advisor

Troubleshoot Kubernetes in A Snap with Sysdig Monitor Advisor

In this webinar, you will learn how Advisor can quickly show you some of the most important information you need to solve difficult Kubernetes problems

A Comprehensive Approach to Cloud Threat Detection and Response
A Comprehensive Approach to Cloud Threat Detection and Response

A Comprehensive Approach to Cloud Threat Detection and Response

In this webinar, SANS Sr. Instructor Jake Williams and Mike Isbitski, Director of Cybersecurity Strategy, Sysdig, make the case for implementing a combination of agent-based and agentless cloud-native security tooling, an approach that provides outcomes far superior than either solution on its own.

Securing the DevSecOps Pipeline with Shift Left + Runtime Security
Securing the DevSecOps Pipeline with Shift Left + Runtime Security

Securing the DevSecOps Pipeline with Shift Left + Runtime Security

Modern DevOps teams are adopting GitOps principles: provisioning workloads using infrastructure-as-code (IaC) tools and managing policies as code using open source tools like Open Policy Agent (OPA)

Events

Cloud Native Bergen
Cloud Native Bergen

Cloud Native Bergen

Bergen
Oct 27
Oct 28
KubeCon NA
KubeCon NA

KubeCon NA

Nov 10
Nov 13
ITCM Marbella
ITCM Marbella

ITCM Marbella

Marbella
Nov 18
Nov 20

Whitepapers

Runtime Insights are Key to Shift‑Left Security

Runtime Insights are Key to Shift‑Left Security

This paper explores the importance of runtime insights for shift‑left activities or preventative security, helping you avoid attacks on your organization’s innovation in the cloud.

In Cloud Security, Architecture Matters

In Cloud Security, Architecture Matters

This paper explores the necessity for advanced instrumentation which delivers a comprehensive solution, adept at merging different data sources and enriching collected data to produce valuable insights in real time.

Cybersecurity Strategy Must Include Both Shift-Left and Shield-Right Approaches

Cybersecurity Strategy Must Include Both Shift-Left and Shield-Right Approaches

Cyber attacks are an unfortunate reality in our interconnected world. The art of keeping up with malicious actors is challenging, but even more so with the move to cloud-native technologies. As a result, security is evolving. Developers, DevOps, and cloud teams must now learn a new set of best practices that balance shift-left security and shield-right security approaches to reduce risk. This white paper developed in collaboration with our partner, Snyk, the leader in developer security, describe the underpinnings of modern cybersecurity programs in the world of containers, Kubernetes, and cloud.

Like what you see?