+++ title = "Tetragon - eBPF-based Security Observability and Runtime Enforcement" linkTitle = "Tetragon - eBPF-based Security Observability and Runtime Enforcement" +++
Tetragon is a sub-project under Cillium and a proud CNCF project

eBPF-based Security Observability and Runtime Enforcement

Tetragon is a flexible Kubernetes-aware security observability and runtime enforcement tool that applies policy and filtering directly with eBPF, allowing for reduced observation overhead, tracking of any process, and real-time enforcement of policies.

Tech leaders use Tetragon

  • Palantir Logo
  • FRSCA Logo
  • GitHub Logo
  • Bell Logo
  • G Research Logo
  • Ripple Logo
  • Nationwide Logo

Why Tetragon?

What can Tetragon do?

Cilium Tetragon is a flexible Kubernetes-aware security observability and runtime

Read the documentation
  • Controlling binary execution (e.g. disallow binary execution from /tmp or allow binaries to be executed)
  • Detect Linux Namespace & Privilege Changes
  • Kubernetes Data Exfiltration
  • File Integrity Monitoring
  • And more!
Jedi-Bee illustration

How does Tetragon work?

Tetragon monitors processes, syscalls, file and network activity in the kernel, correlating threats with network data to identify responsible binaries. It shares insights via JSON logs and a gRPC endpoint.

diagram showing Tetragon architecture and interfaces

How to Install Tetragon?

Exciting Updates and Announcements

Get hands-on with Tetragon

Practice using Tetragon labs to detect and respond to system activity events, such as process executions, file access, network I/O

Watch videos on Tetragon Show all videos

Show all videos

Security Bugs

We strongly encourage you to report security vulnerabilities to our private security mailing list: security@cilium.io - first, before disclosing them in any public forums. This is a private mailing list where only members of the Cilium security team are subscribed to, and is treated as top priority.

Report a bug
Jedi Bee sherlock illustration

Telling the Tetragon Story

Creating an abstract, putting a presentation together, or writing a blog post doesn’t come naturally to everyone. If you are eager to tell your Cilium story and need help, we’re here for you.

Not a native speaker and/or not confident about your writing skills? No worries. Bring the story and we’ll help you tell it in an engaging way.

What do you need help with?