# bytedance/Elkeid

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.

Repository: https://github.com/bytedance/Elkeid
Canonical: https://ross.abutalabs.com/products/elkeid
Homepage: https://elkeid.bytedance.com
Language: Go
License Family: other
Topics: hids, security, rasp, edr, cwpp, linux-security
Last push: 2026-05-11T03:51:11+00:00

## Health v2 (maintenance only)
Score: 70/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 81, release rhythm 40, longevity 100
- inputs: {"age_days": 2084, "days_push": 114, "days_rel": 615, "gap_med": 10.0, "n_releases_24m": 9}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2672, forks 477 (observed 2026-08-28T04:07:09.559294+00:00)

## What it is
Elkeid is an open-source cloud workload protection platform from ByteDance that provides host intrusion detection (HIDS), runtime application self-protection (RASP), container/K8s security monitoring, and vulnerability/baseline scanning. It combines a kernel-level data collection driver, on-host agents and plugins, a backend agent center, and the Elkeid HUB rule engine into a unified self-hosted security platform.

## Use cases
- detect intrusions on linux hosts and containers
- monitor kubernetes audit logs for attacks
- protect running applications with RASP without restarting them
- inventory host and container assets
- detect vulnerabilities and weak security baselines on servers
- detect rootkits and kernel-level backdoors
- build custom detection rules with a rule engine

## When to choose
- you need a self-hosted HIDS/EDR covering hosts, containers, and K8s in one platform
- you want kernel-level telemetry and RASP probes derived from large-scale production use
- you need asset inventory, vulnerability, and baseline checks alongside intrusion detection

## When to avoid
- you need a fully turnkey managed product with complete out-of-the-box detection policies
- your fleet is primarily Windows or macOS since Elkeid targets Linux
- you cannot operate a multi-component self-hosted backend (Kafka, Redis, MongoDB, etc.)

## Facets
- artifact type: application
- maturity: active
- function: security, monitoring, alerting, logging
- domain: security, cloud-computing
- platform: self-hosted, go
- tags: hids, edr, rasp, cwpp, intrusion-detection, kernel-driver, k8s-audit, rule-engine, host-security, container-security, containers, devops, linux, docker, kubernetes

## Member repositories
- bytedance/Elkeid (main) score 70

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:09.559294+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:18:06.403172+00:00, confidence not recorded.
  - readme: https://github.com/bytedance/Elkeid (fetched 2026-08-28T04:07:09.559294+00:00, sha 36ba2fc6a0cf)
  - homepage: https://elkeid.bytedance.com (fetched 2026-08-29T10:00:41.462599+00:00, sha 79fc79947b5f)
  - site_page: https://elkeid.bytedance.com/docs/elkeidup/README-zh_CN.html (fetched 2026-08-29T10:00:41.464978+00:00, sha ec6cbcdb700b)
  - site_page: https://elkeid.bytedance.com/docs/index.html (fetched 2026-08-29T10:00:41.466831+00:00, sha 07540b4ed407)
  - site_page: https://elkeid.bytedance.com/blogs/come_see_elkeid_at_black_hat/come_see_elkeid_at_black_hat.html (fetched 2026-08-29T10:00:41.468653+00:00, sha 4f6379191e9e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
