Primary sources connect this project to an EU CSIRT as developer or lead.
At a glance
Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
CIRCL / Kunai Project
Recorded country
Luxembourg
Product model
Open source
Deployment
Desktop/CLI
Software license
GPL-3.0
Upstream status
Active
Evidence class
CSIRT-led
What the sources establish
Origin note
CIRCL’s own technical article explicitly describes developing Kunai for Linux security monitoring. CIRCL is based in Luxembourg; the project also accepts wider contributions.
Reported capabilities
Produces chronologically ordered Linux activity events.
Provides container-aware monitoring in a standalone Rust binary.
Scope and limits
Linux support depends on the documented kernel compatibility. Running eBPF probes requires elevated privileges.
Inspect the research evidence 7 source observations
identity / capabilities / deployment
Upstream documentation describes monitor Linux host and container events with eBPF instrumentation and on-host event enrichment for detection and threat hunting. It documents local installation.
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Documented EU funding
Digital Europe Programme (DEP) · Next Generation Security Operator Training Infrastructure (NGSOTI)
Reference: 101127921
Kunai acknowledges NGSOTI support for the project. The action runs from January 2024 to December 2026; funding by feature is not specified.