HOST SECURITY

Runtime Security

Observe behavior inside running workloads using supported eBPF kprobes and tracepoints. Combine process context, detection rules, and available container metadata to investigate activity beyond HTTP requests.

CAPABILITIES

What it provides

  • Supported execution, file, and connection events such as execve, openat, and connect.
  • Process and parent context, user attributes, and available event details.
  • Detection rules that suppress, escalate, downgrade, or tag events.
  • Monitor, alert, simulation, and supported enforcement modes with container enrichment.

DEPLOYMENT WORKFLOW

How to use it

  1. 01

    Deploy and connect a compatible Linux host agent, then verify active tracing programs.

  2. 02

    Review Runtime Security events and tune detection rules for expected workload behavior.

  3. 03

    Validate the effect of host enforcement policies in monitoring or simulation before enabling a disruptive response.

CONFIGURATION & OPERATION

Where it fits in your setup

Use Runtime Security for event investigation and rule configuration. Docker/containerd integration enriches events when the runtime socket is available; missing enrichment does not turn every event into a container-attributed event.

COVERAGE & LIMITS

What to account for

Coverage depends on attached probes, kernel capabilities, and trace configuration. Supported enforcement mechanisms may terminate matching processes; they are not a universal guarantee that every syscall is blocked before execution.

Put the policy into practice.

Follow the documentation and validate with your own workload.

Open documentation →