kaimon is a file integrity monitoring (FIM) platform built for Linux infrastructure. It uses an eBPF kernel agent to capture every file lifecycle event - create, modify, move, delete, attribute change and write - with full process, user and device context, across bare-metal servers, virtual machines and containerized workloads.
Traditional file integrity monitoring tools push raw filesystem events into a SIEM and expect a security engineer to spend weeks writing suppression rules before the output means anything to an auditor. Most evaluations end before that point, because a tool that reports thousands of routine deployment writes as findings is worse than no tool at all.
kaimon replaces that work with AI-powered automatic baselining. On deployment the agent begins learning immediately. Over seven days it runs progressive, time-staggered analysis to capture every layer of operational noise - container startup artifacts, log rotation, package updates, nightly cron and weekly maintenance - and generates narrowly scoped suppression rules for legitimate activity. On day seven the baseline locks and the system becomes deterministic: anything that does not match established patterns is a genuine anomaly worth investigating.
The baseliner is security-aware by design. It refuses to suppress changes to credential stores, privilege configuration, service unit definitions, SSH key files or system logs, so an attacker cannot teach it to ignore malicious behavior during the learning window.
Built-in detection categories classify anomalies by severity out of the box: unauthorized changes to credential and privilege files, persistence mechanisms including SSH key injection, service backdoors and dynamic linker hijacking, log tampering, kernel module and driver changes, data exfiltration to removable media or via archive creation, permission and ownership manipulation, cron modifications, and package installs outside declared maintenance windows.
Container coverage is native. A single kernel agent resolves overlay filesystem paths for Docker, Kubernetes, containerd, Podman, CRI-O and LXC, with no sidecars, no image modifications and no per-container agents.
Reports are generated daily and map directly to the controls auditors ask about: SOC 2 CC6 and CC7, HIPAA 164.312(c)(1), PCI DSS 10.5.5 and 11.5, and NIST SP 800-53 SI-7. Each carries an AI-written, framework-specific verdict covering workload profile, anomaly assessment and compliance status. Evidence exports as PDF, HTML or JSON, and delivers by webhook to any SIEM, Slack, Discord or email.
An interactive dashboard provides forensic deep search across the entire fleet, filtering by host, user, process and file path, for engineers who need more than an executive summary.
Deployment is a single command. The agent detects the distribution and architecture, verifies checksums, installs, and configures itself. Deploy, baseline, report - with no regex, no rule authoring and no security engineer in the loop.
Who Is the Company Behind kaimon?