Jibril – Runtime security monitoring and enforcement for modern infra
Jibril – Runtime security monitoring and enforcement for modern infra
Jibril is a runtime security monitoring and enforcement tool. It introduces a new architecture designed to overcome limitations of previous-generation runtime security tooling and EDRs, which were primarily built for traditional endpoints and long-running containerized workloads. Jibril introduces an event-less architecture leveraging eBPF to maintain lightweight state maps directly within the kernel. Instead of buffering events, it queries kernel state directly, enabling real-time detection and enforcement with minimal overhead. This approach is especially effective for protecting ephemeral and cloud-native infrastructure against emerging threats that exploit low-level system behaviors. The new sensor architecture delivers unique benefits: - Simple deployment with out-of-the-box coverage: deploy instantly in any Linux environment using a single binary—no sidecars, kernel modules, or application code changes required. Integrates seamlessly into existing stacks with minimal dev/ops overhead and includes a comprehensive set of MITRE-mapped runtime detections. - Real-time in-kernel detection & enforcement: enforce behavioural policies directly within the kernel in real-time. Features include live kernel-state querying, freezing suspicious processes, detailed process ancestry, and source-level context. - Lightweight footprint: engineered specifically for modern environments, jibril operates with negligible CPU and memory overhead (typically <5%), ensuring performant visibility and response without the perf impact. This enables modern platform and engineering teams to achieve runtime detection and response at scale, enabling use cases and answering questions such as: - What network calls were made during my GitHub Actions test workflow, and what dependency triggered them? - How can I restrict the python3 process from reading /proc/[pid]/mem to block memory dump attacks in my runner (as seen in the recent tj-actions supply chain attack)? - How can I automatically block malicious DNS resolutions within K8s pods and automatically update cluster firewall rules using managed blocklists (e.g., known cryptomining pools and C2 servers)? You can try it out for free today at https://jibril.garnet.ai/usage/installation . We’re looking forward to your feedback, questions, and suggestions on what we can improve on and build next!
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Reifying infra with comptime, deploytime, runtime
KubeArmor – runtime K8s security with AppArmor
Grafana dashboard for monitoring Golang runtime via Prometheus
A container runtime implemented in x86_64 assembly
Subverting Go's Runtime System
Toggle Methods and Endpoints at Runtime
Mixing C++ with Angelscript for runtime introspection and debugging
Restate, a Distributed Async Runtime
AegisBPF – Deterministic Runtime Enforcement via eBPF LSM
Kern – container and resource runtime in a 1.5 MB binary, no daemon