Built For
Security Monitoring
Feed your SIEM with high quality Linux events.
Threat Hunting
Explore what really happens on your Linux hosts.
Incident Response
Reconstruct process trees and attacker activity.
Detection Engineering
Write and test rules against real events.
What You Get
Rich Security Events
Process execution, file activity, network connections, DNS queries, BPF program loads, module loading, mmap/mprotect with exec rights and more.
Context Out of the Box
Every event comes with process ancestry, parent command line, executable hashes and container information. No post-processing needed.
Detection & Filtering Rules
Write simple YAML rules to tag detections with MITRE ATT&CK ids and severity, or to filter out noise right on the host.
IoCs, YARA & Actions
Match indicators of compromise live, scan files with YARA and trigger actions such as killing a malicious process.
Container Aware
Monitor activity inside your containers and apply all your threat-hunting rules to them seamlessly.
Powered by Rust and eBPF
Built with the Aya library: low overhead, memory safe and running on a wide range of kernels.
How It Works
Detect What Matters
Detection rules are simple YAML files matching on any event field. This one catches binaries masquerading as kernel threads, a technique sometimes used by malware to hide itself.
Write your first rulename: mimic.kthread
type: detection
meta:
tags: [ 'os:linux' ]
attack: [ T1036 ]
match-on:
events:
kunai: [execve, execve_script]
matches:
$task_is_kthread: .info.task.flags &= '0x200000'
$kthread_names: .info.task.name ~= '^(kworker)'
condition: not $task_is_kthread and $kthread_names
severity: 10