SFX

Karzoun Kernwatch

Apache-2.0

What it is

Linux eBPF telemetry agent in C with CO-RE/libbpf, exec/open/connect tracing, PID/UID filtering, NDJSON output, runtime smoke testing, sanitizers and CodeQL.

KernWatch is a Linux eBPF telemetry agent written in C. The v0.1 foundation observes a deliberately bounded set of kernel events and streams them to userspace as newline-delimited JSON (NDJSON). It is not an EDR, does not block activity, and does not claim threat detection. The current goal is to make kernel telemetry collection, filtering, transport, failure accounting, runtime verification and security boundaries explicit and testable.

Engineering characteristics

  • Automated tests
  • Continuous integration
  • Documentation set
  • Open licence
  • Release pipeline
  • Security policy

Testing

The repository contains an automated test suite that runs as part of its checked-in workflow.

Security

The repository publishes a security policy describing how to report vulnerabilities.

Deployment

The repository defines its own build and deployment automation.

Documentation

The repository ships a dedicated documentation set beyond the README.

Topics

asanbpfcclangcodeqlcore-ebpfebpfkernelkernel-observabilitylibbpflinuxllvmnetwork-tracingobservabilityopen-sourceprocess-tracingring-buffersystems-programmingtelemetryubsan

← All projects