Voltar ao ranking

cilium/tetragon

Ctetragon.io

eBPF-based Security Observability and Runtime Enforcement

bpfebpfkernelkubernetessecurity
Crescimento de estrelas
Estrelas
4.8k
Forks
571
Crescimento semanal
Issues
122
2k4k
abr. de 2022set. de 2023fev. de 2025jul. de 2026
README

License License License


Cilium’s new Tetragon component enables powerful real-time, eBPF-based Security Observability and Runtime Enforcement.

Tetragon detects and is able to react to security-significant events, such as

  • Process execution events
  • System call activity
  • I/O activity including network & file access

When used in a Kubernetes environment, Tetragon is Kubernetes-aware - that is, it understands Kubernetes identities such as namespaces, pods and so on - so that security event detection can be configured in relation to individual workloads.

Tetragon Overview Diagram

See more about how Tetragon is using eBPF.

Getting started

Refer to the official documentation of Tetragon.

To get started with Tetragon, take a look at the getting started guides to:

Tetragon is able to observe critical hooks in the kernel through its sensors and generates events enriched with Linux and Kubernetes metadata:

  1. Process lifecycle: generating process_exec and process_exit events by default, enabling full process lifecycle observability. Learn more about these events on the process lifecycle use case page.
  2. Generic tracing: generating process_kprobe, process_tracepoint and process_uprobe events for more advanced and custom use cases. Learn more about these events on the TracingPolicy concept page and discover multiple use cases like:

See further resources:

Join the community

Join the Tetragon 💬 Slack channel and the 📅 Community Call to chat with developers, maintainers, and other users. This is a good first stop to ask questions and share your experiences.

How to Contribute

For getting started with local development, you can refer to the Contribution Guide. If you plan to submit a PR, please "sign-off" your commits.

Adopters

A list of adopters of the Tetragon project and who is deploying it in production, and of their use cases, can be found in the USERS.md file.

Repositórios relacionados
cilium/cilium

eBPF-based Networking, Security, and Observability

GoGo ModulesApache License 2.0containersbpf
cilium.io
24.8k3.9k
bpftrace/bpftrace

High-level tracing language for Linux

C++Apache License 2.0bpfebpf
bpftrace.org
10.2k1.5k
capstone-engine/capstone

Capstone disassembly/disassembler framework for ARM, ARM64 (ARMv8), Alpha, BPF, Ethereum VM, HPPA, LoongArch, M68K, M680X, Mips, MOS65XX, PPC, RISC-V(rv32G/rv64G), SH, Sparc, SystemZ, TMS320C64X, TriCore, Webassembly, XCore and X86.

Creverse-engineeringdisassembler
capstone-engine.org
8.9k1.7k
qmonnet/awesome-ebpf

A curated list of awesome projects related to eBPF.

Creative Commons Zero v1.0 Universalawesome-listawesome
5.1k437
hengyoush/kyanos

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes troubleshooting more efficient.

CApache License 2.0command-line-toolebpf
kyanos.io
5k231
parca-dev/parca

Continuous profiling for analysis of CPU and memory usage, down to the line number and throughout time. Saving infrastructure cost, improving performance, and increasing reliability.

TypeScriptnpmApache License 2.0pprofprofiling
parca.dev
4.9k252
aya-rs/aya

Aya is an eBPF library for the Rust programming language, built with a focus on developer experience and operability.

Rustcrates.ioApache License 2.0ebpfbpf
aya-rs.dev/book/
4.7k455
aquasecurity/tracee

Linux Runtime Security and Forensics using eBPF

GoGo ModulesApache License 2.0ebpflinux
aquasecurity.github.io/tracee/latest
4.6k504
zoidyzoidzoid/awesome-ebpf

A curated list of awesome projects related to eBPF.

Creative Commons Zero v1.0 Universalawesome-listawesome
4.5k383
eunomia-bpf/bpf-developer-tutorial

eBPF Developer Tutorial: Learning eBPF Step by Step with Examples

CMIT Licensebpfebpf
eunomia.dev/tutorials/
4.2k590
cilium/pwru

Packet, where are you? -- eBPF-based Linux kernel networking debugger

CApache License 2.0linuxnetwork
3.8k229
the-tcpdump-group/tcpdump

the TCPdump network dissector

COtherpcappcapng
tcpdump.org
3.2k928