GitHub ↗
Flagship · Rust · eBPF

Behavioral ransomware detection that answers with a kill signal.

talus-process-monitor hooks syscall tracepoints in the Linux kernel, scores per-process open-rates in one-second windows and terminates the encryptor with SIGKILL — guardrailed, whitelist-aware, and never at the cost of the host. One static binary. No kernel modules. No telemetry.

Buy Enterprise — $50/node Deployment guide Source ↗

$50 per node · 12 months of updates · license key delivered on checkout · VAT invoice via Polar

~280k
events per second, single core
7.6%
sustained CPU under synthetic load
<1s
verdict to SIGKILL, same second
188
tests in the CI suite, every push
What it does

Three layers, one binary.

Detection is the easy half. Talus ships the half nobody writes up: the response path.

Detect: behavior, not signatures

Mass file-opens scored per process in 1s windows; canary reads, mass-delete and exfiltration-spike detectors. Signature-free — catches strains nobody has named yet.

Respond: SIGKILL in the same second

When the verdict fires, the offending process is killed immediately. Guardrails, per-path whitelists and canary verification keep it fast without being reckless.

Contain: Landlock & seccomp self-sandboxing

The agent sandboxes itself before it starts watching: no kernel modules, no writable footprint outside its own directory, verified by its own tests.

Ship: SIEM, Kafka, ClickHouse, MemGraph

Forward alerts as RFC5424 or CEF, stream raw events to Kafka, persist to ClickHouse, explore process lineage in MemGraph. Self-hosted, your infrastructure.

Sixty-second start

From pip to live dashboard.

pip install talus-process-monitor
talus-monitor install
sudo talus --web 10.0.0.5:8443
talus-monitor selftest --canary

The canary self-test simulates a ransomware burst with harmless file operations and prints the real verdict — detection proof on your hardware in under a minute. Full flags and tuning: /docs.

Pricing

Priced like a tool, not like a platform.

$50 / node / year

Enterprise tier — one host, one year of updates.

  • Web dashboard, REST API, WebSocket event stream
  • Auto-kill response engine with guardrails
  • SIEM forwarding (RFC5424 / CEF), Kafka, ClickHouse, MemGraph
  • License key delivered instantly on checkout
  • Email support — 48h business-day response
  • Detection engine stays MIT, forever
Checkout — $50

Component licensing

Detection engine (eBPF, scoring, sweep detectors)MIT — free
Dashboard, REST API, WebSocket$50/node
Auto-kill response path$50/node
SIEM / Kafka / ClickHouse / MemGraph sinks$50/node
SourcePublic, MIT

MSPs & resellers

Batch prepaid keys at the $50 floor, your margin above, your pricing. Write to [email protected] for the vendor order form — net-30 available on direct invoice.

Supply chain

Verifiable end-to-end.

Every release ships with an SBOM and build attestation; provenance is continuous, not advertised in slide decks.

SBOM (SPDX)

Full dependency inventory attached to every release asset.

Build attestation

Sigstore-style provenance linking source commit to published binary.

OpenSSF Scorecard

Supply-chain posture measured continuously on the flagship repository.

Verify a release Releases ↗