<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>威胁检测 on 黄文卓 | DevOps Engineer</title><link>https://socake.github.io/tags/%E5%A8%81%E8%83%81%E6%A3%80%E6%B5%8B/</link><description>Recent content in 威胁检测 on 黄文卓 | DevOps Engineer</description><generator>Hugo -- gohugo.io</generator><language>zh-CN</language><managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor><webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster><copyright>© 2026 Wenzhuo Huang</copyright><lastBuildDate>Fri, 03 Oct 2025 09:30:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/%E5%A8%81%E8%83%81%E6%A3%80%E6%B5%8B/index.xml" rel="self" type="application/rss+xml"/><item><title>Falco 运行时安全实战：从规则开发到生产级调优</title><link>https://socake.github.io/posts/falco-runtime-security-deep/</link><pubDate>Fri, 03 Oct 2025 09:30:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/falco-runtime-security-deep/</guid><description>一份来自生产环境的 Falco 实战笔记：从 eBPF 驱动选型、规则开发方法论、误报治理，到与 Falcosidekick、Loki、SIEM 的告警联动，覆盖 0.40/0.41/0.42 三个版本的关键变更与真实踩坑案例。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/falco-runtime-security-deep/featured.jpg"/></item></channel></rss>