+
Skip to content

كتاب - kitab (book) - Source code for jibril.garnet.ai - A living book of guidance and knowledge, illuminating the path for all who seek to understand and protect their systems.

Notifications You must be signed in to change notification settings

garnet-org/jibril-kitab

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

19 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

icon layout
shield
title description tableOfContents outline pagination
visible
visible
visible
true
visible
true
visible

Jibril

Use Cases

What is it ?

Jibril is a cutting-edge runtime monitoring and threat detection engine, designed to deliver real-time insights with minimal impact on system performance. Powered by eBPF, it remains efficient even under heavy event loads exceeding hundreds of thousands of events per second–delivering real-time protection for modern environments from dev to prod.

Mission

  • Ensure the security and integrity of your systems at runtime.
  • Deliver clear and actionable insights

Insights

Deep Visibility on Root Causes

{% hint style="info" %} Key Benefits

  • High Performance: Maintains efficiency with extensive event loads.
  • Full Visibility: Tracks all system resources comprehensively.
  • Security: Ensures robust security and tamper-evident data integrity.
  • Seamless Integration: Easily integrates with existing infrastructure. {% endhint %}

Jibril in less than 5 Minutes

{% embed url="https://www.youtube.com/watch?v=xGT3yiXBC3E" %} Install and Configure Jibril in Less than 5 Minutes {% endembed %}


Main Features

Navigate the tabs for the main features.

{% tabs %} {% tab title="Detailed Info" %} Detailed Security Event Information

Jibril provides comprehensive tracking across all system resources, including users, processes, files, and network connections. Its query-driven architecture ensures complete visibility and actionable intelligence into system behavior.

Context Information
(OS Package Versions)

Triggerer Ancestry Visibility
FULL File Access History

Track OS Package Dependencies Versions
Detection FULL Context
On Demand CVE Warnings

{% endtab %}

{% tab title="Noise Filtering" %} Prioritized Detections with Noise Filtering

Jibril has an automatic mechanism to reduce noise. Repetitive alerts are filtered by its nature. Some detections are limited by amount of times they happened on the same parent process, some others are limited by amount of times they happened by the same executable path, and so on.

{% include ".gitbook/includes/untitled.md" %} {% endtab %}

{% tab title="Network Visibility" %} Inbound and Outbound connections tied to Security Events

Complete View of Remote Peers Per Process
Detections are Linked With Corresponding Remote Peer
Full DNS Resolution Path per Peer and Flow

All Processes Communicating with the same Remote Node Are Grouped
All Detections are Flagged on Each Entry (linked with Detections Feature)

{% endtab %}

{% tab title="Block Traffic" %} Network Policy Enforcement

Block Network Connections Using Domains or IP CIDRs.
Get Bad Reputation Domains Alerts Realtime.

{% endtab %} {% endtabs %}

About

كتاب - kitab (book) - Source code for jibril.garnet.ai - A living book of guidance and knowledge, illuminating the path for all who seek to understand and protect their systems.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 2

  •  
  •  
点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载