Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rst13
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
rst13
1y ago
Thanks for the detailed reply! I see custom policy/assertions on kernel behavior as powerful. As a current osquery user managing a fleet of 10k+ hosts (mostly Linux boxes) I find the query model resonates in terms of ux. We have a set
2.
▲
by
rst13
1y ago
Intrigued by your "real-time kernel-level enforcement" (like freezing suspicious processes). Sounds powerful, but also risky—how do you prevent false positives from bringing down legitimate workloads? Is there a built-in policy tu
3.
▲
by
rst13
2y ago
Thanks for the detailed reply! The arch and perf gains sound compelling. It might be a bit early for benchmarks, but I'd be curious to see how argus compares vis-à-vis other ebpf-based introspection tools at scale, in terms of stabilit
4.
▲
by
rst13
2y ago
Interesting take. I’ve been looking a lot into hardening build clusters for our dev teams. We’re a k8s shop and use a mix of egress controls, host isolation, and Falco for detections (although we’ve had stability issues running the sidecar
5.
▲
by
rst13
5y ago
Unfortunately this is something large corps like AWS have been getting away with for a while now. Releasing half-baked product clones as GA when in fact they're still clunky and are probably beta at max.
6.
▲
by
rst13
5y ago
I wonder how Netlify is doing in comparison
7.
▲
by
rst13
5y ago
Great tool! Having used wireshark for ages, its refreshing to visualize binaries like this
8.
▲
by
rst13
5y ago
I've been using Garnet with my k8s setup. They don't have native kube api integration and I suggest developing a controller. But right now you can use the CLI to append any commands or scripts in your docker containers to supply t