kunai-project/kunai
Threat-hunting tool for Linux observed · 2026-08-28
Health v2 · maintenance only
81/100
- Activity 99
- Release rhythm 56
- Longevity 83
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 20.0
- age_days: 1169
- days_rel: 294
- days_push: 9
- n_releases_24m: 11
Adoption not part of the score
1084 stars · 79 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Kunai is an eBPF-based threat-hunting and security-monitoring tool for Linux, often described as the Linux counterpart to Sysmon on Windows. It captures kernel-level events with eBPF probes and delivers chronologically ordered, enriched, and correlated events in a self-contained Rust binary that is also container-aware.
Use cases
- monitor Linux system events for security threats
- hunt for malicious activity on Linux hosts
- get a Sysmon-like event stream on Linux
- trace container activity with eBPF
- correlate and enrich kernel events for incident response
- detect suspicious process and file activity in real time
When to choose
- you need kernel-level event monitoring on Linux with a single standalone binary
- you want container-aware security telemetry
- you need chronologically ordered, correlated events for threat hunting
- you prefer a Rust/eBPF (Aya-based) tool over kernel modules
When to avoid
- you need security monitoring on Windows or macOS
- your kernel is too old or incompatible with eBPF probes
- you need a full SIEM or alerting pipeline rather than an event source
- you cannot run the tool with elevated (root) privileges
Facets
cli-tool · maturity active
monitoring security developer-tools security monitoring operating-systems cli rust ebpf threat-hunting security-monitoring sysmon-for-linux container-aware rust aya event-monitoring edr containers linux
9 sources
- readme: https://github.com/kunai-project/kunai · fetched 2026-08-28 · d3382347f65b
- homepage: https://why.kunai.rocks · fetched 2026-08-29 · 1889034cdfc6
- site_page: https://why.kunai.rocks/docs/quickstart · fetched 2026-08-29 · 2ae574410f1d
- site_page: https://why.kunai.rocks/docs/next/quickstart · fetched 2026-08-29 · 2a6dcc8e8b98
- site_page: https://why.kunai.rocks/docs/0.5.0/quickstart · fetched 2026-08-29 · 52d02dc625c7
- site_page: https://why.kunai.rocks/docs/0.4.0/quickstart · fetched 2026-08-29 · 7fc7634ff3cd
- site_page: https://why.kunai.rocks/docs/0.3.0/quickstart · fetched 2026-08-29 · ba3891fefbb0
- site_page: https://why.kunai.rocks/docs/0.2.0/quickstart · fetched 2026-08-29 · b918a1e0ef89
- site_page: https://why.kunai.rocks/docs/0.1.0/quickstart · fetched 2026-08-29 · 7a70156f8323
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| kunai-project/kunai | main | 81 |
For agents
markdown · JSON · MCP: product_card(name="kunai-project/kunai")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem