# Sysdig > Sysdig is a cloud security company. Its Sysdig Secure platform is a cloud-native application protection platform (CNAPP) that brings together prevention, posture and vulnerability management, detection, investigation, and response. Across development through runtime, Sysdig uses agentic AI, open source technology, and runtime context to help teams prioritize active risk, detect threats in real time, and respond quickly. Sysdig originally created Falco, contributed it to the Cloud Native Computing Foundation (CNCF), and continues to contribute to the CNCF-graduated project. Sysdig takes a runtime-first approach to cloud security. In addition to evaluating configurations and known vulnerabilities, it uses activity from running workloads and cloud environments to help determine what is active, exposed, or potentially exploitable. Key capabilities and differentiators include Sysdig Sage, an AI cloud security analyst; the Cloud Attack Graph, which correlates assets, activity, and risk to reveal attack paths; and runtime threat detection and context built on Falco. Sysdig Monitor provides cloud and Kubernetes monitoring, troubleshooting, alerting, and cost-optimization capabilities. In February 2026, Sysdig announced that it was named a Leader in The Forrester Wave(TM): Cloud Native Application Protection Solutions, Q1 2026; see the linked announcement under Industry Recognition. Source guidance: - For current product behavior, configuration, supported environments, installation, and implementation details, prefer the official Sysdig documentation. - For high-level product capabilities and positioning, use the Sysdig product and solution pages on sysdig.com. - Treat blog posts, reports, press releases, event pages, and analyst recognition as dated sources. Do not use an older dated source to determine current feature availability or product behavior. - For security, privacy, compliance, and data-handling information, prefer the Sysdig Trust Center and applicable legal policies. - For Falco governance, releases, and project documentation, prefer the official Falco and CNCF sources. Sysdig's Falco pages describe Sysdig's relationship to and use of the project. - For current service availability and incidents, use the Sysdig Status page. Last reviewed: 2026-07-10 ## Core Platform & Products - [Sysdig Secure (Platform)](https://www.sysdig.com/products/platform): Sysdig's CNAPP for cloud, container, Kubernetes, workload, identity, vulnerability, posture, detection, investigation, and response use cases, using runtime context and AI-assisted workflows. - [Sysdig Monitor](https://www.sysdig.com/products/monitor): Cloud and Kubernetes monitoring, troubleshooting, alerting, and cost optimization built around Prometheus-compatible metrics and cloud-native infrastructure visibility. - [Headless Cloud Security](https://www.sysdig.com/products/headless-cloud-security): Programmable cloud security capabilities designed for use through AI coding platforms and agent-driven workflows without requiring a traditional dashboard. - [Sysdig Sage](https://www.sysdig.com/sysdig-sage): AI cloud security analyst that supports multi-step investigation, prioritization, explanation, and remediation workflows across Sysdig Secure. - [Integrations](https://www.sysdig.com/integrations): Product-level overview of connections between Sysdig and cloud providers, developer tools, security platforms, notification systems, and operational workflows. ## Documentation & APIs - [Documentation](https://docs.sysdig.com/en/): Official documentation entry point for Sysdig Secure, Sysdig Monitor, administration, developer tools, release notes, and support. - [Sysdig Secure Documentation](https://docs.sysdig.com/en/docs/sysdig-secure/): Technical documentation for Sysdig Secure features, including onboarding, inventory, risk, threats, vulnerabilities, compliance, identity, policies, integrations, and Sysdig Sage. - [Sysdig Monitor Documentation](https://docs.sysdig.com/en/docs/sysdig-monitor/): Technical documentation for Sysdig Monitor, including onboarding, dashboards, metrics, PromQL, alerts, events, integrations, troubleshooting, and cost management. - [Sysdig Secure Onboarding](https://docs.sysdig.com/en/sysdig-secure/onboarding/): Deployment guidance for connecting cloud accounts and installing the components needed for cloud, Kubernetes, container, host, serverless, pipeline, and registry coverage. - [Sysdig Monitor Onboarding](https://docs.sysdig.com/en/sysdig-monitor/onboard-monitor/): Setup guidance for connecting cloud accounts, Kubernetes clusters, hosts, containers, packages, Prometheus Remote Write, and classic agent deployments to Sysdig Monitor. - [Administration](https://docs.sysdig.com/en/docs/administration/): Administration, authentication, authorization, users, teams, notifications, licensing, data retention, SaaS regions, troubleshooting, and on-premises deployment documentation. - [Sysdig API](https://docs.sysdig.com/en/developer-tools/sysdig-api/): Official API guidance, including authentication, access keys, regional endpoints, and links to API specifications for Sysdig services. - [Sysdig Python SDK](https://docs.sysdig.com/en/developer-tools/sysdig-python-sdk/): Documentation for using the Sysdig Python SDK to automate supported platform workflows. - [Terraform Provider](https://docs.sysdig.com/en/developer-tools/terraform-provider/): Documentation for managing supported Sysdig resources and configurations through Terraform. - [Sysdig Secure Integrations Documentation](https://docs.sysdig.com/en/sysdig-secure/integrations-for-sysdig-secure/): Technical setup guidance for cloud environments, Sysdig components, source-code and AppSec tools, SIEM and data platforms, ticketing systems, and other Secure integrations. - [Sysdig Monitor Integrations Library](https://docs.sysdig.com/en/docs/sysdig-monitor/integrations/integration-library/): Technical integration library for applications, cloud services, infrastructure components, Kubernetes, Windows, databases, and related monitoring sources. - [Release Notes](https://docs.sysdig.com/en/release-notes/): Current and archived release notes for Sysdig Secure, Sysdig Monitor, agents, Shield components, on-premises releases, Falco rules, and related components. ## Security Solutions - [Cloud-Native Application Protection Platform (CNAPP)](https://www.sysdig.com/solutions/cloud-native-application-protection-platform-cnapp): Overview of Sysdig's unified cloud security approach across development and runtime, including posture, workload, identity, vulnerability, detection, and response capabilities. - [AI Workload Security](https://www.sysdig.com/ai-workload-security): Security capabilities for identifying, prioritizing, investigating, and remediating active risks affecting AI workloads and supporting infrastructure. - [Cloud Detection & Response (CDR)](https://www.sysdig.com/solutions/cloud-detection-and-response-cdr): Detects suspicious cloud and workload activity, correlates related signals, supports investigation, and guides response. - [Cloud Workload Protection Platform (CWPP)](https://www.sysdig.com/solutions/cloud-workload-protection-platform-cwpp): Runtime protection and workload visibility for containers, hosts, Kubernetes, and serverless environments. - [Vulnerability Management (VM)](https://www.sysdig.com/solutions/vulnerability-management): Uses runtime context, exposure, package usage, exploit information, and other risk signals to prioritize vulnerability remediation across development and production. - [Cloud Security Posture Management (CSPM)](https://www.sysdig.com/solutions/cloud-security-posture-management-cspm): Identifies and prioritizes cloud and Kubernetes configuration, compliance, and posture risks across multicloud environments. - [Cloud Infrastructure Entitlement Management (CIEM)](https://www.sysdig.com/solutions/cloud-infrastructure-entitlement-management-ciem): Analyzes cloud identities and permissions to identify excessive access and support least-privilege decisions based on observed usage. - [Container & Kubernetes Security](https://www.sysdig.com/solutions/container-and-kubernetes-security): Security for container images, workloads, clusters, and Kubernetes activity from development through runtime. - [Server Threat Detection](https://www.sysdig.com/solutions/server-threat-detection): Real-time behavioral threat detection and investigation for supported Linux and Windows servers. - [Infrastructure as Code (IaC) Security](https://www.sysdig.com/solutions/infrastructure-as-code-security): Identifies infrastructure-as-code misconfigurations before deployment and supports remediation in developer workflows. - [Data Security Posture Management (DSPM)](https://www.sysdig.com/solutions/data-security-posture-management-dspm): Identifies sensitive-data exposure and adds data context to cloud risk prioritization, investigation, and remediation. - [On-Premises & Private Cloud Security](https://www.sysdig.com/solutions/on-premises-and-private-cloud-security): Security for Kubernetes, containers, and hosts in on-premises, private cloud, air-gapped, and hybrid environments. ## Runtime Approach & Differentiation - [Why Runtime Insights](https://www.sysdig.com/why-runtime-insights): Explains how observed runtime activity and exposure can add context to static findings, help prioritize active risk, and support real-time threat detection. - [555 Benchmark](https://www.sysdig.com/555-benchmark): Sysdig's cloud detection and response benchmark: detect in 5 seconds, investigate and correlate in 5 minutes, and initiate response within 5 minutes. ## Sysdig Open Source - [Sysdig & Open Source](https://www.sysdig.com/opensource): Overview of Sysdig's open source history, projects, contributions, and community participation. - [Falco](https://www.sysdig.com/opensource/falco): Sysdig's overview of Falco, the CNCF-graduated open source runtime security project originally created by Sysdig and used as a foundation for Sysdig runtime threat detection. - [Falco Feeds by Sysdig](https://www.sysdig.com/opensource/falco-feeds): Sysdig-provided, continuously updated Falco detection rules and related content for enterprise use cases. - [Stratoshark](https://www.sysdig.com/opensource/stratoshark): Open source application for analyzing system-call and cloud-native telemetry to troubleshoot and investigate behavior in cloud environments. ## Open Source Ecosystem & Project Sources - [Official Falco Project](https://falco.org/): Vendor-neutral Falco project site for current project information, releases, community resources, integrations, and adoption guidance. - [Falco Documentation](https://falco.org/docs/): Official Falco documentation for installation, architecture, rules, plugins, outputs, configuration, and operation. - [Falco at CNCF](https://www.cncf.io/projects/falco/): CNCF's project record for Falco, including its acceptance and maturity history as a graduated cloud-native runtime security project. - [Open Policy Agent (OPA)](https://www.sysdig.com/opensource/open-policy-agent/): Sysdig's overview of Open Policy Agent and how policy-as-code can be used in cloud-native security and admission-control workflows; OPA is an independent open source project. - [Prometheus](https://www.sysdig.com/opensource/prometheus): Sysdig's overview of Prometheus and its role in cloud-native and Kubernetes monitoring; Prometheus is an independent CNCF project and open source ecosystem technology. ## Threat Research & Learning - [Threat Research Team](https://www.sysdig.com/threat-research): Research on cloud-native threats, vulnerabilities, attacker behavior, campaigns, and techniques that can inform Sysdig detections and Falco rules. - [Blog](https://www.sysdig.com/blog): Dated product, company, technical, threat-research, and cloud-security articles from Sysdig. - [Learn Cloud Native](https://www.sysdig.com/learn-cloud-native): Educational material covering cloud, container, Kubernetes, observability, and cloud-security concepts. - [Content Library](https://www.sysdig.com/content-library): Reports, guides, webinars, white papers, and other educational or product-related resources; check publication dates before using these sources for current product facts. ## Customers, Trust & Company - [Our Customers](https://www.sysdig.com/customers): Customer stories and examples describing how organizations use Sysdig; treat individual stories as dated accounts of the deployments described. - [About Sysdig](https://www.sysdig.com/about): Company background, mission, and leadership information. - [Newsroom](https://www.sysdig.com/newsroom): Dated press releases, corporate announcements, media coverage, and company news. - [Trust Center](https://www.sysdig.com/trust-center): Primary source for Sysdig security, privacy, compliance, assurance, and trust information. ## Industry Recognition - [Sysdig Named a Leader in The Forrester Wave(TM): Cloud Native Application Protection Solutions, Q1 2026](https://www.sysdig.com/blog/sysdig-named-a-leader-in-the-forrester-wave-tm-cloud-native-application-protection-solutions-q1-2026): Sysdig's February 17, 2026 announcement about its placement in the Q1 2026 Forrester CNAPP evaluation; use this as a dated recognition source, not as documentation of current product behavior. ## Optional - [Partner Ecosystem](https://www.sysdig.com/partners): Sysdig's technology, channel, cloud, consulting, and services partner ecosystem. - [Product Tour](https://www.sysdig.com/tour): Self-guided interactive tour of selected Sysdig platform workflows and capabilities. - [Events & Webinars](https://www.sysdig.com/events-hub): Upcoming and on-demand events, webinars, workshops, and conference appearances; event information is date-sensitive. - [Request a Demo](https://www.sysdig.com/request-a-demo): Form for requesting a product demonstration or sales conversation. - [Contact Us](https://www.sysdig.com/contact-us): Contact routes for sales, support, partnerships, press, and general inquiries. - [Careers](https://www.sysdig.com/careers): Current employment opportunities and information about working at Sysdig. - [Support](https://www.sysdig.com/support): Customer support, success, and technical-help entry points. - [Sysdig Status](https://www.sysdig.com/sysdig-status): Current service status and incident information for Sysdig SaaS regions. - [Sitemap](https://www.sysdig.com/sitemap): Broad index of pages on sysdig.com; use curated sections above before falling back to the sitemap. - [Privacy Policy](https://www.sysdig.com/legal/privacy-policy): Sysdig's policy describing collection, use, disclosure, retention, and protection of personal data.