Ross ROSS = Recommend OSS · open-source software intelligence for agents

bytedance/Elkeid

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices. observed · 2026-08-28

github.com/bytedance/Elkeid · homepage · Go observed · 2026-08-28

Health v2 · maintenance only

70/100

  • Activity 81
  • Release rhythm 40
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 10.0
  • age_days: 2084
  • days_rel: 615
  • days_push: 114
  • n_releases_24m: 9

Full methodology

Adoption not part of the score

2672 stars · 477 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Elkeid is an open-source cloud workload protection platform from ByteDance that provides host intrusion detection (HIDS), runtime application self-protection (RASP), container/K8s security monitoring, and vulnerability/baseline scanning. It combines a kernel-level data collection driver, on-host agents and plugins, a backend agent center, and the Elkeid HUB rule engine into a unified self-hosted security platform.

Use cases

  • detect intrusions on linux hosts and containers
  • monitor kubernetes audit logs for attacks
  • protect running applications with RASP without restarting them
  • inventory host and container assets
  • detect vulnerabilities and weak security baselines on servers
  • detect rootkits and kernel-level backdoors
  • build custom detection rules with a rule engine

When to choose

  • you need a self-hosted HIDS/EDR covering hosts, containers, and K8s in one platform
  • you want kernel-level telemetry and RASP probes derived from large-scale production use
  • you need asset inventory, vulnerability, and baseline checks alongside intrusion detection

When to avoid

  • you need a fully turnkey managed product with complete out-of-the-box detection policies
  • your fleet is primarily Windows or macOS since Elkeid targets Linux
  • you cannot operate a multi-component self-hosted backend (Kafka, Redis, MongoDB, etc.)

Facets

application · maturity active

security monitoring alerting logging security cloud-computing self-hosted go hids edr rasp cwpp intrusion-detection kernel-driver k8s-audit rule-engine host-security container-security containers devops linux docker kubernetes

5 sources

Member repositories

RepositoryRoleHealth v2
bytedance/Elkeidmain70

For agents

markdown · JSON · MCP: product_card(name="bytedance/Elkeid")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem