Skip to content

Add Talus to Security section - #172

Open
BartoszOsiej wants to merge 1 commit into
qmonnet:mainfrom
BartoszOsiej:main
Open

BartoszOsiej wants to merge 1 commit into
qmonnet:mainfrom
BartoszOsiej:main

Conversation

@BartoszOsiej

Copy link
Copy Markdown

Adds Talus to the Security section.

Talus is an eBPF-based ransomware detection and response agent for Linux, written in Rust with Aya:

  • behavioural detection: per-PID sliding-window scoring of file-open rates over eBPF tracepoints (execve/openat/unlink/mkdir + network events)
  • automated response: SIGKILL of the offending process when the verdict fires, with an observe-only mode for tuning
  • self-sandboxing agent: drops to CAP_BPF|CAP_PERFMON|CAP_NET_ADMIN, seccomp allowlist, Landlock read-only FS rules
  • single static binary (~2 MB), no kernel modules, no runtime dependencies

MIT licensed. Happy to adjust the entry wording or placement if the maintainers prefer.

@BartoszOsiej

Copy link
Copy Markdown
Author

Opened this a while back and it is still accurate - the numbers in the description are re-measured, not copied. If the format of the list changed since, say so and I will rebase it in a day.

For context on the claims: this is the only entry I have open, after I closed the duplicate requests I had out there. Happy to answer anything about the implementation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant