{"repo":"tarsal-oss/kflowd","free":true,"listed":false,"github":"https://github.com/tarsal-oss/kflowd","clone":"git clone https://github.com/tarsal-oss/kflowd.git","description":"Kernel-based Process Monitoring on Linux Endpoints for File System, TCP and UDP Networking Events and optionally DNS, HTTP and SYSLOG Application Messages via eBPF Subsystem","language":"C","stars":75,"topics":["co-re","detection","dlp","dns","dpi","ebpf","edr","filesystem","http","monitoring"],"license":"GPL-2.0","category":"analytics","readme_excerpt":"Kernel-based Process Monitoring on Linux Endpoints via eBPF kflowd runs as agent on Linux endpoints to monitor processes via eBPF kernel subsystem for filesystem and TCP and UDP networking events, enabling immediate threat and anomaly detection on suspicious activities. Advanced non-ebpf related features such as DNS, HTTP and SYSLOG application message decoding, checksum calculation for virus detection, process and file versioning for vulnerability detection and file device, network interface and user-group identification for files and processes can be enabled via open-binary plugin modules. Pre-built kflowd and kflowd-plugins packages can be downloaded for quick installation from the Releases section. If you would like to join our community Slack channel please send an email to devs@tarsal.co to receive an invitation. You can also contact us directly at kflow@tarsal.co for any questions. kflowd contains an eBPF program running in kernel context and its control application running in userspace. The eBPF program traces kernel functions to monitor processes based on file system and networking events. Events are aggregated into records and submitted into a ringbuffer where they are polled by the userspace control application. All Records are enriched with process information and then converted into a message in JSON output format. Final messages are printed to stdout console and can be sent via UDP protocol to specified hosts for ingestion in a security data pipeline. kflowd run","default_branch":null,"files":null,"tree":[],"storefront":"/r/tarsal-oss","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/tarsal-oss/kflowd/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}