Skip to content

garnet-org/jibril-howtos

Repository files navigation

icon layout
heart
width title description tableOfContents outline pagination metadata
default
visible
visible
visible
true
visible
visible
visible

Welcome

Jibril is a cutting-edge runtime monitoring and threat detection engine, designed to deliver real-time insights with minimal impact on systems performance. Powered by eBPF, it remains efficient even under heavy event loads exceeding hundreds of thousands of events per second–delivering real-time protection for modern environments from dev to prod.

FeatureKey Benefits
High PerformanceMaintains efficiency even under extensive event loads
Lower OverheadSignificantly less overhead than its counter parts
Complete ContextComprehensive context for deep forensic analysis on each event
More Detections100+ built-in detection rules available
2M+ tracked bad reputation domains
Seamless IntegrationFlexible output options for SIEM systems, logs, files, and APIs
Reduced NoiseAI-powered filters false positives and enhances events using LLMs
GitOps ReadyManage detection recipes through git repositories
Custom DetectionsCreate and manage detection recipes using YAML
ReactionsUse javascript to program reactions to detection events

About

Jibril documentation (gitbook sync).

Resources

License

Stars

Watchers

Forks