Jibril is a cutting-edge runtime monitoring and threat detection engine, designed to deliver real-time insights with minimal impact on system performance. Powered by eBPF, it remains efficient even under heavy event loads exceeding hundreds of thousands of events per second–delivering real-time protection for modern environments from dev to prod. Jibril's query-driven eBPF approach, unlike traditional event-streaming models, collects kernel behavioral data with minimal overhead, eliminating performance bottlenecks while maintaining monitoring integrity.
Jibril is a cutting-edge runtime monitoring and threat detection engine, designed to deliver real-time insights with minimal impact on system performance. Powered by eBPF, it remains efficient even under heavy event loads exceeding hundreds of thousands of events per second–delivering real-time protection for modern environments from dev to prod. Jibril's query-driven eBPF approach, unlike traditional event-streaming models, collects kernel behavioral data with minimal overhead, eliminating performance bottlenecks while maintaining monitoring integrity.
## Read more:
The 3rd Generation EDR with in-depth context: - https://jibril.garnet.ai/jibril/readme/new-era
Why Jibril out performs other runtime engines: - https://jibril.garnet.ai/jibril/readme/theory-behind
## Give it a try:
Command Line - https://jibril.garnet.ai/jibril/installation/command-line
Systemd service - https://jibril.garnet.ai/jibril/installation/systemd-service
Docker Container - https://jibril.garnet.ai/jibril/installation/docker-containe...
Kubernetes - https://jibril.garnet.ai/jibril/installation/kubernetes
## Features
Create your own detection recipes (Alchemies) using YAML - https://jibril.garnet.ai/jibril/components/alchemies/create-...
Reduce false positives using The Attenuator (powered by AI) - https://jibril.garnet.ai/jibril/components/attenuator
Block network using the network policy - https://jibril.garnet.ai/jibril/components/network-policy
## Repositories
Find our public repositories - https://jibril.garnet.ai/jibril/installation/repositories
Unmarshal detection events using the public types package - https://github.com/garnet-org/jibril-ashkaal
Find & Share public detection recipes - https://github.com/garnet-org/jibril-wahy