diff --git a/readme.md b/readme.md index 6bb1504..ef30fc6 100644 --- a/readme.md +++ b/readme.md @@ -350,6 +350,7 @@ If you are new to eBPF, you may want to try the links described as "introduction - [Synapse](https://github.com/gen0sec/synapse) - Extended detection and response (XDR) with eBPF-powered firewall and proxy, to protect your Linux servers. - [BPFJailer](https://github.com/gen0sec/bpfjailer) - BpfJailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. - [Bombini](https://github.com/bombinisecurity/bombini) - An eBPF-based security agent written entirely in Rust using the [Aya](https://github.com/aya-rs/aya) library and built on LSM (Linux Security Module) BPF hooks. +- [talus](https://github.com/BartoszOsiej/talus-process-monitor) - A ransomware detection and response agent for Linux. Watches file events through eBPF, scores behaviour (fast rewrites, rename chains, entropy spikes) and kills offending processes, without kernel modules. - [owLSM](https://github.com/Cybereason-Public/owLSM) - Open source agent that implements a stateful Sigma rules engine focused on monitoring and prevention using eBPF LSM. - [Inner Warden](https://github.com/InnerWarden/innerwarden) - A self-defending security agent for Linux and macOS that uses eBPF with 22 kernel hooks (tracepoints, kprobes, LSM, XDP) via the Aya library for real-time threat detection, automated response, and AI-powered triage.