Jibril – Runtime security monitoring and enforcement for modern infra
Jibril is a runtime security monitoring and enforcement tool. It introduces a new architecture designed to overcome limitations of previous-generation runtime security tooling and EDRs, which were primarily built for traditional endpoints and long-running containerized workloads. Jibril introduces an event-less architecture leveraging eBPF to maintain lightweight state maps directly within the kernel. Instead of buffering events, it queries kernel state directly, enabling real-time detection and enforcement with minimal overhead. This approach is especially effective for protecting ephemeral…
In plain words
Jibril is a runtime security monitoring and enforcement tool for modern cloud infrastructure. It uses an event-less architecture with eBPF technology to maintain kernel-level state maps, enabling real-time threat detection and enforcement with minimal performance overhead. Designed to protect ephemeral and cloud-native workloads that existing endpoint detection tools handle poorly, Jibril deploys as a single binary across Linux environments without requiring sidecars or kernel modules.
written from the facts on this page · September 2026
From the sources
In the maker’s words, at launch
Jibril is a runtime security monitoring and enforcement tool. It introduces a new architecture designed to overcome limitations of previous-generation runtime security tooling and EDRs, which were primarily built for traditional endpoints and long-running containerized workloads. Jibril introduces an event-less architecture leveraging eBPF to maintain lightweight state maps directly within the kernel. Instead of buffering events, it queries kernel state directly, enabling real-time detection and enforcement with minimal overhead. This approach is especially effective for protecting ephemeral and cloud-native infrastructure against emerging threats that exploit low-level system behaviors. The new sensor architecture delivers unique benefits: - Simple deployment with out-of-the-box coverage: deploy instantly in any Linux environment using a single binary—no sidecars, kernel modules, or application code changes required. Integrates seamlessly into existing stacks with minimal dev/ops overhead and includes a comprehensive set of MITRE-mapped runtime detections. - Real-time in-kernel detection & enforcement: enforce behavioural policies directly within the kernel in real-time. Features include live kernel-state querying, freezing suspicious processes, detailed process ancestry, and source-level context. - Lightweight footprint: engineered specifically for modern environments, jibril operates with negligible CPU and memory overhead (typically <5%), ensuring performant visibility and response without the perf impact. This enables modern platform and engineering teams to achieve runtime detection and response at scale, enabling use cases and answering questions such as: - What network calls were made during my GitHub Actions test workflow, and what dependency triggered them? - How can I restrict the python3 process from reading /proc/[pid]/mem to block memory dump attacks in my runner (as seen in the recent tj-actions supply chain attack)? - How can I automatically block malicious DNS resolutions within K8s pods and automatically update cluster firewall rules using managed blocklists (e.g., known cryptomining pools and C2 servers)? You can try it out for free today at https://jibril.garnet.ai/usage/installation. We’re looking forward to your feedback, questions, and suggestions on what we can improve on and build next!
More life & fun this month
the category →- TL
Life & fun · 10d ago · louisabraham.github.io

Photosynthesis fires two of your iPhone
Life & fun · 28d ago · photosynthesis.camera
SoloUno▲310Take control of hair pulling, nail biting & skin picking
Life & fun · 28d ago · solouno.io

Scroll through all 43,252,003,274,489,856,000 reachable Rubik's Cube permutations.
Life & fun · 26d ago · everycube.alen.is


Hi HN, I built Eigendrum, a web tool that solves the 2D wave equation for arbitrary shapes so you can hear what they sound like as drums. How it works: * Solves -∇²u = λu using finite element analysis (Kφ = λMφ) on a triangle mesh. * Validated to <0.1% error against closed-form solutions for circles (Bessel zeros) and rectangles. * Sound model factors in strike location, Rayleigh damping, and mallet width. * Includes Kac drums I & II to demonstrate identical sound spectra from different geometries. * No frameworks, build steps, or dependencies. Repo and tests:…
Life & fun · 27d ago · baselashraf81.github.io
Launched alongside, March 2025
the whole month →
Mimic Human Research & Save Findings in AI Knowledge Base
AI · 2025 · sider.ai




