Research · Tag · Falco
Posts tagged falco.
1 entry · sorted: recency← All research
RESEARCH
2026-07-23
What syscall-layer tooling cannot see in P2P infrastructure: a technique-by-technique analysis
If you run Falco, an EDR, or a generic host agent on a validator and a network-DoS attack against the node went undetected, this explains why. A technique-by-technique analysis of five reproduced P2P-infrastructure attacks against the syscall detection surface. Zero are detectable as attributable rules, and the reasons are structural, not a matter of tuning.
Simon Morley
Read →13 min read
