You can do the same rule - based activity detection through Falco which is also open source. https://github.com/draios/falco
Note that both of these open source projects originate from Sysdig as well.