Detection and monitoring CSIRT-led

Kunai

Monitor Linux host and container events with eBPF instrumentation and on-host event enrichment for detection and threat hunting.

By CIRCL / Kunai Project · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
CIRCL / Kunai Project
Recorded country
Luxembourg
Product model
Open source
Deployment
Desktop/CLI
Software license
GPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

CIRCL’s own technical article explicitly describes developing Kunai for Linux security monitoring. CIRCL is based in Luxembourg; the project also accepts wider contributions.

Reported capabilities

  • Produces chronologically ordered Linux activity events.
  • Provides container-aware monitoring in a standalone Rust binary.

Scope and limits

Linux support depends on the documented kernel compatibility. Running eBPF probes requires elevated privileges.

Inspect the research evidence 7 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes monitor Linux host and container events with eBPF instrumentation and on-host event enrichment for detection and threat hunting. It documents local installation.

    Read source
  2. origin / country

    The Kunai developer organisation identifies its location as Luxembourg. CIRCL also lists Kunai in its own open-source project inventory.

    Read source
  3. license

    The upstream license file specifies GPL-3.0.

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-10-08. This is an activity signal, not a support guarantee.

    Read source
  5. deployment

    The quick-start documents running the local executable with privileges and links kernel compatibility requirements.

    Read source
  6. origin

    CIRCL includes Kunai in its project portfolio.

    Read source
  7. origin / country

    CIRCL explicitly says it developed Kunai and describes the project; the page identifies CIRCL as Luxembourg’s response centre.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection