Product Overview

Linux runtime security.
Built for what matters.

RuntimeGuard is a focused Linux runtime security platform that detects ransomware behaviour in real time. It combines lightweight kernel-level telemetry with behavioural detection and practical containment — built for modern server environments.

Start free trial → View Architecture
Core capabilities
What RuntimeGuard does
Five layers of protection that work together — from data collection to incident response.
01

Monitors process activity

Every process execution on your Linux hosts is observed at kernel level via eBPF tracepoints. No agent per process. No performance overhead. Everything from exec calls to short-lived scripts.

02

Tracks file behaviour

File write and rename activity is continuously monitored. When a process starts writing or renaming files at abnormal rates — a hallmark of ransomware encryption — RuntimeGuard catches it immediately.

03

Detects ransomware patterns

Behavioural detection rules run against a sliding time window. File write bursts, rename storms, and process execution anomalies all trigger incidents — catching ransomware before it completes.

04

Creates incident timelines

Every incident is recorded with a full timeline: which process triggered it, which files were affected, when it started. Your team has everything needed to investigate and respond.

05

Automated containment

When detection confidence is high, RuntimeGuard can automatically terminate the offending process — stopping encryption mid-flight. Available in Growth and Business tiers.

06

Multi-tenant management

Built for MSPs and multi-environment teams. Manage multiple customers or environments from a single control plane with full data isolation between tenants.

07

Threat intelligence enrichment

Every outbound connection and executed binary is checked against a cascade of threat intelligence sources: Feodo Tracker, Emerging Threats, MalwareBazaar, VirusTotal and AlienVault OTX. Matches generate critical incidents automatically.

08

DNS exfiltration detection

Raw DNS traffic is captured via AF_PACKET and analysed using Shannon entropy. High-entropy subdomains and abnormal query rates indicate DNS tunnelling — the covert channel most security tools miss entirely.

09

Custom Sigma-compatible rules

Write your own detection rules in Sigma YAML alongside the 26 built-in rules. Rules are validated on save, support field modifiers and compound conditions, and run against every event in real time.

10

Process tree / attack graph

Every incident links to an interactive process tree showing the full parent–child ancestry of the offending process in the ±5-minute window. Follow the chain from a suspicious shell back to root cause without touching the host.

11

Role-based access control

Admin, analyst and viewer roles are enforced at the API key level. Assign the right access to every team member — operations, security analysts and read-only stakeholders — with full audit logging of every action.

12

SSO / OIDC authentication

Enterprise teams can log in with their existing Google Workspace or Microsoft Entra identity — no separate credentials to manage. RBAC roles apply to SSO identities and sessions are tenant-scoped.

13

MSP / MSSP portal

Managed service providers get a cross-tenant SOC feed, unified admin panel and per-tenant drill-down — all from a single login. Volume pricing available for MSPs with more than five tenants.

Why behaviour-based
Signatures fail. Behaviour doesn't.
Traditional antivirus relies on known malware signatures. Attackers have known this for years — modern ransomware is customised, obfuscated, and changes constantly.

Signature-based tools

Fail against new or customised variants
Require continuous signature updates
High false negative rate on novel malware
Built for Windows endpoints, not Linux servers
Complex deployment with kernel modules
Often flag benign software incorrectly

RuntimeGuard

Detects what malware does, not what it looks like
No signature database — no update lag
Catches zero-day ransomware by behaviour
Built specifically for Linux server workloads
Single eBPF agent, no kernel modules
Low false positive rate — focused rules
By the numbers
Why Linux protection can't wait
68%
of ransomware attacks in 2024 targeted Linux infrastructure
4.2M
average cost of a ransomware incident for mid-size businesses
<60s
time for RuntimeGuard to detect a file encryption burst in progress
Comparison
How RuntimeGuard stacks up
Capability RuntimeGuard Wazuh (OSS) Falco (OSS) Crowdstrike
Linux runtime monitoring
eBPF kernel-level telemetry
Ransomware-specific detectionpartialpartial
Managed SaaS (no self-hosting)
Sliding window detection
Multi-tenant (MSP-ready)complex
Deploy in < 5 minutespartial
SMB-friendly pricingfreefree
Threat intelligence (VT + OTX)partial
DNS exfiltration detectionpartial
Custom Sigma rulespartial
Process tree / attack graph
RBAC rolescomplex
SSO / OIDC login

Ready to protect your
Linux infrastructure?

Start a 14-day free trial. No credit card required. Deploy in minutes.