Product
OpenStealth Defense for Linux.
Our original anti-rootkit platform: behavioral cross-view detection, real-time eBPF monitoring, and SIEM-ready reporting for Linux servers and cloud VMs — built from the same kernel research behind our Android integrity work.
Product demo
See the detection platform in action.
What it does
Inspect, explain, validate.
- Behavioral cross-view detection: /proc vs. kill-probe, modules vs. /sys, sockets vs. /proc/net — catches unknown rootkits by their effects, not their names
- Signature catalog covering 30+ known rootkit families (KoviD, Diamorphine, Reptile, Drovorub, eBPF rootkits and more)
- Real-time eBPF monitoring: kprobes and tracepoints for module loads, process lifecycle, syscalls, and network events
- Rootkit artifacts matched with embedded YARA rules; CVE monitoring against NVD for observed kernel versions
- SIEM-ready output: JSON, CEF (ArcSight), syslog over UDP/TCP, Slack and webhook alerts, plus a TUI dashboard
- Deployment your way: Debian and RPM packages, systemd service, Docker — plus a raw C fallback scanner for older kernels
Know what is running on your kernels.
Whether you run a handful of servers or a fleet of cloud VMs, OpenStealth Defense gives you evidence-grade visibility into rootkits and kernel-level tampering.