Elkeid is an open-source platform for security and intrusion-detection that aims to support a wide variety of deployment contexts — from bare-metal hosts to containers, Kubernetes clusters, and even serverless environments. It was born out of ByteDance’s internal security best practices, offering for community users a subset of its enterprise-grade capabilities. Elkeid combines kernel-level data collection, user-space agents, and runtime instrumentation (RASP) to detect malicious behavior, file anomalies, runtime exploits, and suspicious container activity. For container or cloud-native workloads, it also supports gathering audit logs from Kubernetes and correlating events across processes, network, and file activity to detect security threats. The platform packages data collection, event-streaming, and a rule/event engine (called “HUB”) — letting users define detection rules, alerts, baseline checks, and policy enforcement.

Features

  • Kernel-level data collection for hosts and containers (processes, file I/O, network, system calls)
  • Runtime Application Self-Protection (RASP) for instrumenting live applications (supports multiple languages/runtimes)
  • Host-Intrusion Detection and static malware/ file integrity scanning (e.g. via YARA scanning)
  • Kubernetes/K8s audit-log collection and container-aware intrusion detection, for cloud-native workloads
  • Rule-/event-engine (HUB) that lets users define custom detection rules and alerting workflows
  • Agent-server architecture with centralized management, agent control, and event aggregation for scalable deployment

Project Samples

Project Activity

See All Activity >

Follow Elkeid

Elkeid Web Site

Other Useful Business Software
Stop Storing Third-Party Tokens in Your Database Icon
Stop Storing Third-Party Tokens in Your Database

Auth0 Token Vault handles secure token storage, exchange, and refresh for external providers so you don't have to build it yourself.

Rolling your own OAuth token storage can be a security liability. Token Vault securely stores access and refresh tokens from federated providers and handles exchange and renewal automatically. Connected accounts, refresh exchange, and privileged worker flows included.
Try Auth0 for Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Elkeid!

Additional Project Details

Operating Systems

Linux, Mac, Windows

Programming Language

Go

Related Categories

Go Artificial Intelligence Software

Registered

2025-12-01