Ji

Jibril – Runtime security monitoring and enforcement for modern infra

Hacker News

Jibril – Runtime security monitoring and enforcement for modern infra

Jibril is a runtime security monitoring and enforcement tool. It introduces a new architecture designed to overcome limitations of previous-generation runtime security tooling and EDRs, which were primarily built for traditional endpoints and long-running containerized workloads. Jibril introduces an event-less architecture leveraging eBPF to maintain lightweight state maps directly within the kernel. Instead of buffering events, it queries kernel state directly, enabling real-time detection and enforcement with minimal overhead. This approach is especially effective for protecting ephemeral and cloud-native infrastructure against emerging threats that exploit low-level system behaviors. The new sensor architecture delivers unique benefits: - Simple deployment with out-of-the-box coverage: deploy instantly in any Linux environment using a single binary—no sidecars, kernel modules, or application code changes required. Integrates seamlessly into existing stacks with minimal dev/ops overhead and includes a comprehensive set of MITRE-mapped runtime detections. - Real-time in-kernel detection & enforcement: enforce behavioural policies directly within the kernel in real-time. Features include live kernel-state querying, freezing suspicious processes, detailed process ancestry, and source-level context. - Lightweight footprint: engineered specifically for modern environments, jibril operates with negligible CPU and memory overhead (typically <5%), ensuring performant visibility and response without the perf impact. This enables modern platform and engineering teams to achieve runtime detection and response at scale, enabling use cases and answering questions such as: - What network calls were made during my GitHub Actions test workflow, and what dependency triggered them? - How can I restrict the python3 process from reading /proc/[pid]/mem to block memory dump attacks in my runner (as seen in the recent tj-actions supply chain attack)? - How can I automatically block malicious DNS resolutions within K8s pods and automatically update cluster firewall rules using managed blocklists (e.g., known cryptomining pools and C2 servers)? You can try it out for free today at https://jibril.garnet.ai/usage/installation . We’re looking forward to your feedback, questions, and suggestions on what we can improve on and build next!

Share card

Actual performance

20points
13comments
Made the leaderboard

Launch Intel predictions

Analyze your own launch →
Indie HackersFits the IH revenue-focused audience · Missing: supports, reddit linkedin, podcasting
93%93% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Product HuntOn track for Day 1 leaderboard · Strong signals: new, context, single · Missing: mac, agents, macos
88%88% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
Hacker NewsStrong engagement from HN community · Strong signals: exist, existing, ide · Missing: https docs, excited, just released
69%69% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
AppSumoStrong fit for a featured deal · Strong signals: platform, calls · Missing: plus, intuitive, reviews
55%55% predicted probability of success on AppSumo, based on ML models trained on real launch data.
TrustMRRLess likely to generate early MRR · Missing: mobile apps, ios, personal
32%32% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
9%9% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Strong signals: crypto, introduce · Missing: web3, chat, cryptocurrency
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

Re
Reifying infra with comptime, deploytime, runtime70%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Reifying infra with comptime, deploytime, runtime

Hacker News2
Ku
KubeArmor – runtime K8s security with AppArmor50%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

KubeArmor – runtime K8s security with AppArmor

Hacker News2
Gr
Grafana dashboard for monitoring Golang runtime via Prometheus44%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Grafana dashboard for monitoring Golang runtime via Prometheus

Hacker News1
A
A container runtime implemented in x86_64 assembly55%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

A container runtime implemented in x86_64 assembly

Hacker News3
Su
Subverting Go's Runtime System47%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Subverting Go's Runtime System

Hacker News2
To
Toggle Methods and Endpoints at Runtime48%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Toggle Methods and Endpoints at Runtime

Hacker News2
Mi
Mixing C++ with Angelscript for runtime introspection and debugging59%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Mixing C++ with Angelscript for runtime introspection and debugging

Hacker News1
Re
Restate, a Distributed Async Runtime55%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Restate, a Distributed Async Runtime

Hacker News2
Ae
AegisBPF – Deterministic Runtime Enforcement via eBPF LSM35%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

AegisBPF – Deterministic Runtime Enforcement via eBPF LSM

Hacker News2
Ke
Kern – container and resource runtime in a 1.5 MB binary, no daemon43%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Kern – container and resource runtime in a 1.5 MB binary, no daemon

Hacker News70