implementing-runtime-security-with-tetragon skill (Anthropic-Cybersecurity-Skills)
- Install
- SKILL.md (verbatim)
- Overview
- When to Use
- Prerequisites
- Core Concepts
- eBPF-Based Security
- TracingPolicy Custom Resources
- Enforcement Actions
- Installation and Configuration
- Step 1: Install Tetragon with Helm
- Step 2: Install the Tetragon CLI
- Step 3: Verify Installation
- Practical Implementation
- Detecting Container Escape Attempts
- Monitoring Sensitive File Access
- Blocking Crypto-Miner Execution
- Observing Events with Tetra CLI
- Integration with SIEM and Alerting
- Export to Elasticsearch
- Prometheus Metrics
- Key Metrics and Alerts
- References
- Other files in this skill
- assets/template.md (verbatim)
- Cluster Information
- Pre-Deployment Checklist
- Deployment Configuration
- Helm Values
- TracingPolicy Inventory
- Baseline Metrics
- Detection Validation Results
- Risk Findings
- Critical
- High
- Medium
- Recommendations
- Sign-Off
- references/api-reference.md (verbatim)
- TracingPolicy CRD
- Tetra CLI Commands
- Event Types
- Key Libraries
- references/standards.md (verbatim)
- Industry Standards
- NIST SP 800-190: Application Container Security Guide
- CIS Kubernetes Benchmark v1.9
- MITRE ATT&CK for Containers
- CNCF Landscape Positioning
- Key Differentiators
- Compliance Mapping
- references/workflows.md (verbatim)
- Deployment Workflow
- Phase 1: Observation Mode
- Phase 2: Detection Policies
- Phase 3: Enforcement
- TracingPolicy Development Workflow
- Incident Response Integration
- When Tetragon Detects a Threat
- Forensic Data Collection
- Operational Runbook
- Daily Checks
- Weekly Checks
- Monthly Checks
What it does. Implements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls, and blocking dangerous calls at the kernel level. Use when deploying Tetragon to detect or block syscalls such as ptrace, mount, and unshare, enforcing kernel-level policy, or adding low-overhead runtime detection to a cluster. Keywords: Tetragon, Cilium, eBPF, TracingPolicy, kprobe, enforcement, process lineage. Do not use for Falco-based detection - use detecting-container-runtime-threats-with-falco. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/implementing-runtime-security-with-tetragon/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-runtime-security-with-tetragon, or copy the skill folder into~/.claude/skills/implementing-runtime-security-with-tetragon/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-runtime-security-with-tetragon/SKILL.md
SKILL.md (verbatim)
name: implementing-runtime-security-with-tetragon
description: >-
Implements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with
Cilium Tetragon, monitoring process execution, file access, network connections, and
syscalls, and blocking dangerous calls at the kernel level. Use when deploying Tetragon to
detect or block syscalls such as ptrace, mount, and unshare, enforcing kernel-level policy,
or adding low-overhead runtime detection to a cluster. Keywords: Tetragon, Cilium, eBPF,
TracingPolicy, kprobe, enforcement, process lineage. Do not use for Falco-based detection -
use detecting-container-runtime-threats-with-falco.
domain: cybersecurity
subdomain: container-security
tags:
- tetragon
- ebpf
- runtime-security
- kubernetes
- cilium
- container-security
- observability
- kernel-security
- cncf
version: '1.0'
author: mahipal
license: Apache-2.0
nist_ai_rmf:
- MEASURE-2.7
- MAP-5.1
- MANAGE-2.4
atlas_techniques:
- AML.T0070
- AML.T0066
- AML.T0082
nist_csf:
- PR.PS-01
- PR.IR-01
- ID.AM-08
- DE.CM-01
mitre_attack:
- T1610
- T1611
- T1609
- T1525
Implementing Runtime Security with Tetragon
Overview
Tetragon is a CNCF project under Cilium that provides flexible Kubernetes-aware security observability and runtime enforcement using eBPF. By operating at the Linux kernel level, Tetragon can monitor and enforce policies on process execution, file access, network connections, and system calls with less than 1% performance overhead -- far more efficient than traditional user-space security agents.
When to Use
- When deploying or configuring implementing runtime security with tetragon capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Kubernetes cluster v1.24+ with Helm 3.x installed
- Linux kernel 5.4+ (5.10+ recommended for full eBPF feature support)
- kubectl access with cluster-admin privileges
- Familiarity with eBPF concepts and Kubernetes security primitives
Core Concepts
eBPF-Based Security
Tetragon attaches eBPF programs directly to kernel functions, enabling:
- Process lifecycle tracking: Monitor every process creation, execution, and termination across all pods
- File integrity monitoring: Detect unauthorized reads/writes to sensitive files
- Network observability: Track all TCP/UDP connections with full pod context
- System call filtering: Enforce policies on dangerous syscalls like ptrace, mount, or unshare
TracingPolicy Custom Resources
Tetragon uses TracingPolicy CRDs to define what kernel events to observe and what actions to take:
apiVersion: cilium.io/v1alpha1
kind: TracingPolicy
metadata:
name: detect-privilege-escalation
spec:
kprobes:
- call: "security_bprm_check"
syscall: false
args:
- index: 0
type: "linux_binprm"
selectors:
- matchBinaries:
- operator: "In"
values:
- "/bin/su"
- "/usr/bin/sudo"
- "/usr/bin/passwd"
matchNamespaces:
- namespace: Pid
operator: NotIn
values:
- "host_ns"
matchActions:
- action: Post
Enforcement Actions
Tetragon can take three types of actions directly in the kernel:
- Sigkill: Immediately terminate the offending process
- Signal: Send a configurable signal to the process
- Override: Override the return value of a kernel function to deny an operation
Installation and Configuration
Step 1: Install Tetragon with Helm
helm repo add cilium https://helm.cilium.io
helm repo update
helm install tetragon cilium/tetragon \
--namespace kube-system \
--set tetragon.enableProcessCred=true \
--set tetragon.enableProcessNs=true \
--set tetragon.grpc.address="localhost:54321"
Step 2: Install the Tetragon CLI
GOOS=$(go env GOOS)
GOARCH=$(go env GOARCH)
curl -L --remote-name-all \
https://github.com/cilium/tetragon/releases/latest/download/tetra-${GOOS}-${GOARCH}.tar.gz
tar -xzvf tetra-${GOOS}-${GOARCH}.tar.gz
sudo install tetra /usr/local/bin/
Step 3: Verify Installation
kubectl get pods -n kube-system -l app.kubernetes.io/name=tetragon
tetra status
Practical Implementation
Detecting Container Escape Attempts
Create a TracingPolicy to detect processes attempting to escape container namespaces:
apiVersion: cilium.io/v1alpha1
kind: TracingPolicy
metadata:
name: detect-container-escape
spec:
kprobes:
- call: "__x64_sys_setns"
syscall: true
args:
- index: 0
type: "int"
- index: 1
type: "int"
selectors:
- matchNamespaces:
- namespace: Pid
operator: NotIn
values:
- "host_ns"
matchActions:
- action: Sigkill
Monitoring Sensitive File Access
Detect reads of sensitive credentials:
apiVersion: cilium.io/v1alpha1
kind: TracingPolicy
metadata:
name: monitor-sensitive-files
spec:
kprobes:
- call: "security_file_open"
syscall: false
args:
- index: 0
type: "file"
selectors:
- matchArgs:
- index: 0
operator: "Prefix"
values:
- "/etc/shadow"
- "/etc/kubernetes/pki"
- "/var/run/secrets/kubernetes.io"
matchActions:
- action: Post
Blocking Crypto-Miner Execution
Prevent known crypto-mining binaries from executing:
apiVersion: cilium.io/v1alpha1
kind: TracingPolicy
metadata:
name: block-cryptominers
spec:
kprobes:
- call: "security_bprm_check"
syscall: false
args:
- index: 0
type: "linux_binprm"
selectors:
- matchBinaries:
- operator: "In"
values:
- "/usr/bin/xmrig"
- "/tmp/xmrig"
- "/usr/bin/minerd"
matchActions:
- action: Sigkill
Observing Events with Tetra CLI
Stream runtime events in real-time:
# Watch all process execution events
kubectl exec -n kube-system ds/tetragon -c tetragon -- \
tetra getevents -o compact --process-only
# Filter events for a specific namespace
kubectl exec -n kube-system ds/tetragon -c tetragon -- \
tetra getevents -o compact --namespace production
# Export events in JSON for SIEM integration
kubectl exec -n kube-system ds/tetragon -c tetragon -- \
tetra getevents -o json | tee /var/log/tetragon-events.json
Integration with SIEM and Alerting
Export to Elasticsearch
# tetragon-helm-values.yaml
export:
stdout:
enabledCommand: true
enabledArgs: true
filenames:
- /var/log/tetragon/tetragon.log
elasticsearch:
enabled: true
url: "https://elasticsearch.monitoring:9200"
index: "tetragon-events"
Prometheus Metrics
Tetragon exposes metrics at :2112/metrics:
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
name: tetragon-metrics
namespace: kube-system
spec:
selector:
matchLabels:
app.kubernetes.io/name: tetragon
endpoints:
- port: metrics
interval: 15s
Key Metrics and Alerts
| Metric | Description | Alert Threshold |
|---|---|---|
tetragon_events_total |
Total security events observed | Spike > 3x baseline |
tetragon_policy_events_total |
Events matching TracingPolicies | Any Sigkill action |
tetragon_process_exec_total |
Process executions tracked | Anomalous new binaries |
tetragon_missed_events_total |
Dropped events due to buffer overflow | > 0 sustained |
References
- Tetragon Official Documentation
- Cilium Tetragon GitHub Repository
- CNCF Tetragon Project Page
- eBPF Security Observability with Tetragon - CoreWeave
- Kubernetes Security: eBPF & Tetragon for Runtime Monitoring
Other files in this skill
- LICENSE
- assets/template.md
- references/api-reference.md
- references/standards.md
- references/workflows.md
- scripts/agent.py
- scripts/process.py
assets/template.md (verbatim)
Tetragon Runtime Security Assessment Template
Cluster Information
| Field | Value |
|---|---|
| Cluster Name | |
| Kubernetes Version | |
| Node Count | |
| Tetragon Version | |
| Kernel Version | |
| Assessment Date | |
| Assessed By |
Pre-Deployment Checklist
- Linux kernel version >= 5.4 (5.10+ preferred)
- BTF (BPF Type Format) enabled in kernel
- Helm 3.x installed and configured
- kubectl access with cluster-admin privileges
- SIEM/log aggregation endpoint configured
- Alerting channels established (PagerDuty, Slack, etc.)
Deployment Configuration
Helm Values
tetragon:
enableProcessCred: true
enableProcessNs: true
grpc:
address: "localhost:54321"
export:
mode: "json"
resources:
limits:
cpu: "1"
memory: "1Gi"
requests:
cpu: "250m"
memory: "256Mi"
TracingPolicy Inventory
| Policy Name | Type | Hooks | Action | Target Namespaces |
|---|---|---|---|---|
| kprobe/tracepoint | Post/Sigkill/Override | |||
Baseline Metrics
| Metric | Value | Date Captured |
|---|---|---|
| Average events/sec per node | ||
| CPU overhead per node (%) | ||
| Memory usage per node (MB) | ||
| Event buffer miss rate |
Detection Validation Results
| Attack Scenario | MITRE ATT&CK ID | Detected | Action Taken | Notes |
|---|---|---|---|---|
| Container escape via nsenter | T1611 | Yes/No | ||
| Crypto-miner execution | T1496 | Yes/No | ||
| Sensitive file read (/etc/shadow) | T1552.001 | Yes/No | ||
| Shell in non-shell container | T1059.004 | Yes/No | ||
| Privilege escalation via sudo | T1548.003 | Yes/No | ||
| Network reconnaissance (nmap) | T1046 | Yes/No |
Risk Findings
Critical
| Finding | Namespace | Pod | Recommended Action |
|---|---|---|---|
High
| Finding | Namespace | Pod | Recommended Action |
|---|---|---|---|
Medium
| Finding | Namespace | Pod | Recommended Action |
|---|---|---|---|
Recommendations
Immediate Actions
- [ ]
Short-term (30 days)
- [ ]
Long-term (90 days)
- [ ]
Sign-Off
| Role | Name | Date | Signature |
|---|---|---|---|
| Security Engineer | |||
| Platform Engineer | |||
| Security Manager |
references/api-reference.md (verbatim)
API Reference: Cilium Tetragon Runtime Security
TracingPolicy CRD
apiVersion: cilium.io/v1alpha1
kind: TracingPolicy
metadata:
name: monitor-sensitive-files
spec:
kprobes:
- call: fd_install
args:
- index: 1
type: file
selectors:
- matchArgs:
- index: 1
operator: Prefix
values: ["/etc/shadow", "/etc/passwd"]
Tetra CLI Commands
| Command | Description |
|---|---|
tetra status |
Tetragon health |
tetra getevents |
Stream events |
tetra tracingpolicy list |
List policies |
Event Types
| Type | Description |
|---|---|
process_exec |
Process execution |
process_exit |
Process termination |
process_kprobe |
Kernel probe trigger |
Key Libraries
| Library | Use |
|---|---|
kubernetes |
K8s API client |
subprocess |
kubectl/tetra CLI |
grpc |
Tetragon gRPC API |
references/standards.md (verbatim)
Standards and References - Runtime Security with Tetragon
Industry Standards
NIST SP 800-190: Application Container Security Guide
- Section 4.2: Runtime monitoring and anomaly detection for containers
- Section 4.4: Container-level network monitoring requirements
- Recommends kernel-level security monitoring for container environments
CIS Kubernetes Benchmark v1.9
- Control 5.7.1: Create administrative boundaries between resources using namespaces
- Control 5.7.3: Apply Security Context to pods and containers
- Control 5.7.4: The default namespace should not be used
MITRE ATT&CK for Containers
- T1611: Escape to Host -- Tetragon detects namespace manipulation attempts
- T1059.004: Command and Scripting Interpreter: Unix Shell -- process execution monitoring
- T1053.007: Container Orchestration Job -- detects unauthorized job creation
- T1496: Resource Hijacking -- crypto-miner detection and blocking
CNCF Landscape Positioning
Tetragon is positioned in the CNCF Runtime Security category alongside:
- Falco (audit-log and syscall-based detection)
- KubeArmor (LSM-based enforcement)
- Tracee (eBPF-based tracing)
Key Differentiators
- Kernel-level filtering reduces event volume before reaching user space
- Native enforcement (Sigkill/Override) without requiring separate enforcement engine
- Deep integration with Cilium for combined network + runtime security
- TracingPolicy CRD for Kubernetes-native policy management
Compliance Mapping
| Requirement | Framework | Tetragon Capability |
|---|---|---|
| Runtime threat detection | PCI DSS 11.5 | TracingPolicy with file integrity monitoring |
| Unauthorized process detection | SOC 2 CC6.8 | Process execution monitoring with namespace context |
| Container isolation enforcement | NIST 800-190 4.2 | Namespace escape detection and blocking |
| Audit trail generation | ISO 27001 A.12.4 | JSON event export to SIEM systems |
| Incident response automation | NIST CSF DE.AE | Real-time Sigkill enforcement on policy violations |
references/workflows.md (verbatim)
Workflows - Runtime Security with Tetragon
Deployment Workflow
Phase 1: Observation Mode
- Install Tetragon with default TracingPolicies (no enforcement)
- Collect baseline process execution data for 7-14 days
- Analyze event patterns to identify normal vs anomalous behavior
- Document expected processes per namespace and workload type
Phase 2: Detection Policies
- Create TracingPolicies for known attack patterns (container escape, privilege escalation)
- Configure event export to SIEM (Elasticsearch, Splunk, or Datadog)
- Build alerting rules based on TracingPolicy matches
- Validate detection accuracy with red team exercises
Phase 3: Enforcement
- Enable Sigkill actions for high-confidence threats (known malware binaries)
- Enable Override actions for dangerous syscalls in non-privileged containers
- Implement graduated response -- alert first, block after confirmation
- Monitor enforcement actions for false positives
TracingPolicy Development Workflow
1. Identify Threat -> Map to MITRE ATT&CK technique
2. Determine Kernel Hook -> kprobe, tracepoint, or LSM hook
3. Define Selectors -> Binary, namespace, capability filters
4. Set Action -> Post (observe), Sigkill (block), Override (deny)
5. Test in Staging -> Deploy to non-production namespace first
6. Validate with Attack Simulation -> Confirm detection
7. Deploy to Production -> Apply via GitOps
8. Monitor False Positives -> Tune selectors as needed
Incident Response Integration
When Tetragon Detects a Threat
- Event is generated with full context (pod, namespace, binary, args, capabilities)
- Event exported to SIEM via JSON log export or Prometheus metric
- SOAR platform receives alert and triggers playbook
- Automated actions: isolate pod network (via Cilium NetworkPolicy), capture forensic data
- Security team receives enriched alert with Kubernetes context
Forensic Data Collection
# Export recent events for a specific pod
tetra getevents --namespace <ns> --pod <pod-name> \
--since 1h -o json > /forensics/tetragon-events.json
# Get process tree for suspicious activity
tetra getevents --process-pid <pid> --ancestors 5 -o compact
Operational Runbook
Daily Checks
- Review
tetragon_missed_events_totalmetric for event buffer overflows - Check Tetragon DaemonSet health across all nodes
- Review new TracingPolicy match counts
Weekly Checks
- Analyze top 10 most frequent event types
- Review enforcement action logs for false positives
- Update TracingPolicies based on new threat intelligence
Monthly Checks
- Performance impact assessment (CPU/memory overhead per node)
- TracingPolicy effectiveness review with red team
- Update Tetragon to latest stable release
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.