Distributed systems
Karzoun Kernwatch
What it is
Linux eBPF telemetry agent in C with CO-RE/libbpf, exec/open/connect tracing, PID/UID filtering, NDJSON output, runtime smoke testing, sanitizers and CodeQL.
KernWatch is a Linux eBPF telemetry agent written in C. The v0.1 foundation observes a deliberately bounded set of kernel events and streams them to userspace as newline-delimited JSON (NDJSON). It is not an EDR, does not block activity, and does not claim threat detection. The current goal is to make kernel telemetry collection, filtering, transport, failure accounting, runtime verification and security boundaries explicit and testable.
Engineering characteristics
- Automated tests
- Continuous integration
- Documentation set
- Open licence
- Release pipeline
- Security policy
Testing
The repository contains an automated test suite that runs as part of its checked-in workflow.
Security
The repository publishes a security policy describing how to report vulnerabilities.
Deployment
The repository defines its own build and deployment automation.
Documentation
The repository ships a dedicated documentation set beyond the README.
Topics
Sections appear only where the repository provides verifiable evidence.
