+++ title = "Tetragon - eBPF-based Security Observability and Runtime Enforcement" linkTitle = "Tetragon - eBPF-based Security Observability and Runtime Enforcement" +++
Tetragon is a flexible Kubernetes-aware security observability and runtime enforcement tool that applies policy and filtering directly with eBPF, allowing for reduced observation overhead, tracking of any process, and real-time enforcement of policies.
eBPF enables deep observability with low performance overhead mitigating risks without the latency introduced by user-space processing.
Tetragon extends Cilium's design by recognizing workload identities like namespace and pod metadata, surpassing traditional observability.
Tetragon offers pre-defined policy libraries for rapid deployment and operational insight, reducing setup time and complexity at scale.
Tetragon blocks malicious activities at the kernel level, closing the window for exploitation without succumbing to TOCTOU attack vectors.
Synchronous monitoring, filtering, and enforcement are performed entirely within the kernel using eBPF.
Tetragon goes beyond traditional monitoring, capturing events like process execution, network communications, and file access.
Tetragon monitors processes, syscalls, file and network activity in the kernel, correlating threats with network data to identify responsible binaries. It shares insights via JSON logs and a gRPC endpoint.
Highlights Innovations in Modern Security Approaches
Practice using Tetragon labs to detect and respond to system activity events, such as process executions, file access, network I/O
John Fastabend & Natalia Reka Ivanko •
Duffie Cooley & Raphaël Pinson •
John Fastabend & Natalia Reka Ivanko •
We've created a slide deck for talks, presentations, and demos on Tetragon. Feel free to use it as-is or customize it to fit your specific needs.
See presentationCreating an abstract, putting a presentation together, or writing a blog post doesn’t come naturally to everyone. If you are eager to tell your Cilium story and need help, we’re here for you.
Not a native speaker and/or not confident about your writing skills? No worries. Bring the story and we’ll help you tell it in an engaging way.