Kubernetes has become the backbone of modern cloud-native applications, but its dynamic nature presents unique security challenges. In this hands-on lab session, we’ll dive deep into securing Kubernetes environments with Falco, the open-source standard for runtime threat detection. This workshop will guide attendees through the end-to-end process of setting up Kubernetes, installing Falco, and building custom detection rules to address evolving Linux threats. You’ll learn how to craft rules tailored to your specific environment, enabling more precise detection of anomalous behaviour and potential threats. Additionally, we’ll introduce Falco Talon, a powerful response engine that integrates seamlessly with Falco to mitigate threats in Kubernetes and the cloud. See how Falco Talon automates threat containment and response, minimising downtime and enhancing your cloud security posture. Whether you’re a Kubernetes beginner or a seasoned user, this session will equip you with practical tools and techniques to detect and respond to threats effectively in your cloud-native environments. I want to keep this session interactive, so ask me anything!