aicoolies logo
Elkeid logo

Elkeid

Kernel-space host intrusion detection system

Share
open-sourceOpen Source
Visit Website →

Elkeid is ByteDance's open-source HIDS for hosts, containers, Kubernetes, and serverless workloads. Its kernel-level data collection via Kprobe hooks captures process lineage, privilege escalation attempts, file access patterns, and network connections with minimal overhead. Includes an Agent for telemetry, Detector for rule evaluation, Controller for policy management, and a Dashboard for alerts and investigation.

Elkeid addresses fundamental limitations of user-space security monitoring by collecting system telemetry directly from the Linux kernel via Kprobe hooks. The kernel-level driver intercepts system calls and kernel events to capture process execution chains, privilege escalation attempts, file access patterns, and network connections with minimal performance overhead. This vantage point reveals information invisible to user-space agents, enabling detection of sophisticated attacks that manipulate processes, exploit kernel vulnerabilities, or use fileless techniques.

The architecture consists of specialized components working together at scale: the Agent collects kernel telemetry and publishes events to Kafka, the Detector evaluates event streams against configurable security rules, the Controller manages detection policies across endpoints, and the Dashboard provides alerting and investigation interfaces. Supporting infrastructure includes Kafka for high-throughput message streaming, Redis for real-time caching, and MongoDB for event storage. This design enables horizontal scaling across thousands of endpoints while maintaining real-time detection latency.

Deployed at ByteDance's massive infrastructure scale, Elkeid has proven its reliability and performance in one of the world's most demanding computing environments. The system handles diverse workload types including traditional servers, Docker containers, Kubernetes clusters, and serverless functions from a single agent. The open-source Apache 2.0 license enables security teams to customize detection rules, integrate with existing SIEM platforms, and extend the codebase for organization-specific requirements.

Pricing

Free and open source under Apache 2.0

Platforms

Linux kernel + Go agents, scalable via Kafka

Categories

Tags

Use Cases

Alternatives

Related Tools

Freestyle logo

Freestyle

Sandboxes for coding agents — Linux VMs, Git, and deploys in one box

Freestyle is YC-backed sandbox infrastructure built for AI coding agents, shipping secure Linux VMs with nested virtualization, Git servers, and one-click web deploys. It lets agents run real workloads, branch repos, and deploy apps under short-lived identities while billing only for active compute. Used in production by vly.ai, Rork, and Vibeflow.

freemium
OpenSRE logo

OpenSRE

Open-source toolkit for building AI SRE incident response agents

OpenSRE is an open-source Python toolkit from Tracer Cloud for building AI SRE agents that investigate and respond to production incidents. It ships with connectors to Prometheus, Grafana, Kubernetes and incident platforms, plus a simulation harness that replays past incidents so teams can benchmark agent accuracy before trusting it on live pager rotations.

open-sourceOpen Source
Magika logo

Magika

AI-powered file-type detection at Google scale

Open-source AI-powered file-type detection tool from Google that uses a custom deep-learning model under a few megabytes to identify more than 200 binary and textual content types in milliseconds, even on a single CPU. Magika ships as a CLI, Python package, JavaScript/TypeScript library, and an ONNX model, achieves around 99% accuracy on its test set, and is already used at Google scale across Gmail, Drive, and Safe Browsing as well as by VirusTotal and abuse.ch.

freeOpen Source
Twill AI logo

Twill AI

Autonomous coding agents that ship while you sleep

Twill is an autonomous coding agent platform that implements features, fixes bugs, and ships pull requests without manual intervention. Uses structured workflow of research, planning, human review, implementation in isolated sandbox, AI code review, then merge. Supports custom agent configurations with multiple LLM providers, isolated dev environments for verification, and integrations with GitHub, Linear, Sentry, Notion, and cloud platforms for end-to-end engineering automation.

freemium
Baseten logo

Baseten

ML inference platform for production AI models

Baseten is the inference platform for deploying AI models at scale with dedicated and pre-optimized model APIs and performance-optimized infrastructure. Specializes in image generation, transcription, text-to-speech, LLM serving, embeddings, and compound AI workloads. Delivers 75% latency reduction with 415ms cold starts and 3000+ concurrent scaling. Available as managed cloud or self-hosted, trusted by Cursor, Notion, Descript, and Sourcegraph for production inference.

api-usage-based
Resolve AI logo

Resolve AI

AI-powered production incident resolution

Resolve AI automates production incident investigation, diagnosis, and remediation acting as an AI SRE that participates in every on-call rotation. Autonomously investigates incidents pursuing multiple hypotheses in parallel, validates against real evidence, creates code snippets and drafts PRs, generates post-mortems, and onboards new teammates with instant answers about code and infrastructure. Drives 5x faster MTTR and 87% faster incident investigations.

paid