peterindia.net Kubernetes / AI-Powered Intrusion Detection
Runtime & behavioral security

AI-Powered Intrusion Detection Tools for Kubernetes

Runtime behavioral defense, eBPF-based system-call monitoring, and AI/ML-driven threat response for containerized and cloud-native workloads -- curated and link-checked, not just listed.

7 tools shown
Falco
Open sourceCNCF GraduatedRuntime Detection & Response

The open-source eBPF engine behind most commercial K8s runtime detection

Watches kernel-level system calls across hosts, containers, and Kubernetes via eBPF, applying customizable rules to flag anomalous behavior in real time. A CNCF graduated project -- not itself ML-driven, but the detection engine several AI-powered commercial platforms (including Sysdig Secure) are built on top of.

Rule/eBPF-based, not ML-driven -- listed as the foundation the AI-native platforms below extend.
Visit site →
Sysdig
AI-poweredRuntime Detection & Response

Falco's creator, commercialized with autonomous AI response agents

Built on the Falco runtime engine (Sysdig created and open-sourced Falco), Sysdig Secure unifies prevention, detection, and response across containers, Kubernetes, identities, and cloud services -- adding AI-driven autonomous agents for threat investigation on top of kernel-level system-call monitoring.

Visit site →
Aqua Security
AI-poweredCNAPP

Code-to-runtime CNAPP with GenAI workload protection

A Cloud Native Application Protection Platform covering Kubernetes and container security from code commit through to runtime enforcement. Its AI-specific layer detects unsafe model behavior and blocks prompt-injection-style attacks against GenAI workloads running in production clusters.

Visit site →
ARMO (Kubescape)
AI-poweredOpen sourceBuilt on Kubescape (CNCF Incubating)AI & Cloud Workload Security

Runtime CADR built on the open-source Kubescape project

ARMO's commercial platform layers Cloud Application Detection and Response (CADR), Kubernetes Security Posture Management, and runtime-reachability vulnerability analysis on top of Kubescape -- the free, CNCF-incubating scanner with 11K+ GitHub stars. Includes dedicated protection for AI/ML workloads running in the cluster.

Visit site →
Wazuh
Open sourceOpen Source XDR / SIEM

Free, fully open-source XDR and SIEM with container security coverage

A completely free, open-source security platform unifying XDR and SIEM for endpoints and cloud workloads -- log analysis, file-integrity monitoring, malware and intrusion detection, and incident response, with container security among its listed use cases. No license cost; community-supported on GitHub, Slack, and Discord.

General-purpose XDR/SIEM, not Kubernetes-specific by design -- included as the open-source alternative to commercial CNAPP suites.
Visit site →
Tigera Calico
Open sourceNetwork Security & Policy

The default K8s CNI, with network policy enforcement and traffic visibility

The most widely-adopted Kubernetes CNI, providing networking plus full Kubernetes network-policy enforcement, WireGuard encryption, and pluggable data planes (eBPF, iptables, nftables). Its Whisker UI visualizes cluster traffic for anomaly analysis, extending consistent security policy to VMs and bare metal alongside containers.

Network-policy and observability layer, not an AI-driven detector -- included because intrusion detection is incomplete without network-layer visibility.
Visit site →
SentinelOne
AI-poweredAI & Cloud Workload Security

Autonomous, AI-native XDR extended to securing AI workloads and agents

SentinelOne's Singularity platform applies autonomous, AI-driven detection and response across endpoints and cloud workloads. This page specifically covers securing AI itself -- employee AI usage, homegrown AI applications, agentic workflows, and AI data/infrastructure -- at machine speed.

Broader cloud/AI security platform; Kubernetes workloads are one part of its coverage, not its sole focus.
Visit site →