How can the real-time threat detection engine “Falco” be effectively operated and used to ensure security in a large-scale cloud-native environment? This presentation focuses on specific operational strategies within Mercari’s environment, where a diverse range of microservices and GKE clusters coexist. It will cover a wide range of practical know-how to address challenges unique to large-scale environments, such as mechanisms for automated cluster registration and rule deployment, structured rule management to prevent false positives, and methods for adding context to alerts to streamline incident response.
Chihiro Hasegawa and Maximilian Frank presented this at the Cloud Native Community Japan: CNAPP Security Meetup 2025-12-16.
- https://cncj-security.connpass.com/event/367233/
For the original Japanese slides see
- https://speakerdeck.com/owlinux1000/da-gui-mo-cloud-nativehuan-jing-niokerufalconoyun-yong