In Linux Everything Is a File. In Threat Detection, Everything Is a Stream.
To detect threats, we need to look at all the events that occur across our infrastructure. The open-source Falco project has historically looked at system calls but can also analyze any streaming log file, such as those provided by cloud and SaaS platforms.