Skip to main content

Kunai

Linux security monitoring and threat hunting, powered by eBPF.

Sysmon-like visibility for Linux: process, file, network and DNS events, enriched, ordered and ready for your SIEM.

execve event
{
"data": {
"ancestors": "/usr/lib/systemd/systemd|/usr/bin/login|/usr/bin/zsh|...",
"parent_exe": "/usr/bin/bash",
"command_line": "mktemp -d -p /tmp/trash",
"exe": {
"path": "/usr/bin/mktemp",
"magic": "ELF 64-bit LSB pie executable, x86-64",
"sha256": "f32938cf25ddd6f6800a8e9b406595534d0eb27993587bbdeee2e83dd97d8406",
"size": 39144,
"...": "..."
},
"...": "..."
},
"info": {
"event": { "source": "kunai", "id": 1, "name": "execve", "...": "..." },
"utc_time": "2025-06-10T14:00:42.814301638Z",
"...": "..."
}
}

Built For

Security Monitoring

Feed your SIEM with high quality Linux events.

Threat Hunting

Explore what really happens on your Linux hosts.

Incident Response

Reconstruct process trees and attacker activity.

Detection Engineering

Write and test rules against real events.

What You Get

Rich Security Events

Process execution, file activity, network connections, DNS queries, BPF program loads, module loading, mmap/mprotect with exec rights and more.

Context Out of the Box

Every event comes with process ancestry, parent command line, executable hashes and container information. No post-processing needed.

Detection & Filtering Rules

Write simple YAML rules to tag detections with MITRE ATT&CK ids and severity, or to filter out noise right on the host.

IoCs, YARA & Actions

Match indicators of compromise live, scan files with YARA and trigger actions such as killing a malicious process.

Container Aware

Monitor activity inside your containers and apply all your threat-hunting rules to them seamlessly.

Powered by Rust and eBPF

Built with the Aya library: low overhead, memory safe and running on a wide range of kernels.

How It Works

Linux KerneleBPF probes capture security relevant activity
→
KunaiReorders, enriches, filters and detects
→
JSON EventsOne event per line, easy to parse
→
Your Stackstdout, file, SIEM, threat-hunting tools

Detect What Matters

Detection rules are simple YAML files matching on any event field. This one catches binaries masquerading as kernel threads, a technique sometimes used by malware to hide itself.

Write your first rule
mimic.kthread.yaml
name: mimic.kthread
type: detection
meta:
tags: [ 'os:linux' ]
attack: [ T1036 ]
match-on:
events:
kunai: [execve, execve_script]
matches:
$task_is_kthread: .info.task.flags &= '0x200000'
$kthread_names: .info.task.name ~= '^(kworker)'
condition: not $task_is_kthread and $kthread_names
severity: 10