Compliance Monitoring

eBPF-powered security monitoring scoped to your Cardholder Data Environment. Detect threats at the kernel level, collect evidence automatically, and generate compliance-ready reports - without the enterprise price tag or the scramble before audits.

PCI DSS 4.0

Monitor your CDE hosts with eBPF security policies that map to PCI DSS 4.0 logging and monitoring requirements.

Req 10 & 11 evidence collection

SOX Evidence

Collect evidence for SOX IT general controls with automated change detection, access logging, and operations monitoring.

Section 302 & 404 ITGC evidence

Requirement 10: Log and monitor all access

The eBPF agent monitors your CDE hosts and maps security events to PCI DSS 4.0 Requirement 10 and 11 controls. Evidence is collected automatically - no manual gathering before audits.

10.2.1

User Access Logging

Capture all access to cardholder data and system components via eBPF file access monitoring.

10.2.1.2

Admin Action Logging

Track all actions by administrators with privileged user activity monitoring.

10.2.1.4

Auth Failure Tracking

Log invalid authentication attempts with automatic brute force detection.

10.3.4

File Integrity Monitoring

Protect audit logs from modification with FIM and real-time alerts on changes.

10.4.1.1

Automated Log Review

AI-powered LLM Security Analyzer provides automated review mechanisms.

10.5.1

12-Month Retention

Retain audit logs for at least one year with ClickHouse time-series storage.

10.6.x

Time Synchronization

NTP monitoring checks ensure synchronized clocks and detect time drift.

10.7.x

Control Health Monitoring

Detect and alert on security control failures with agent health checks.

10.4.3

Alert Escalation

Address exceptions and anomalies with automated escalation system.

Requirement 11: Test security systems regularly

Continuous security testing with eBPF-powered intrusion detection and file integrity monitoring.

11.5.1

Network Intrusion Detection

eBPF network monitoring detects intrusions in real-time at the kernel level. Includes reverse shell detection for covert communication channels (11.5.1.1).

  • Outbound connection monitoring
  • Reverse shell detection
  • MITRE ATT&CK classification
11.5.2

Change Detection Mechanisms

File integrity monitoring with SHA256 hashing detects unauthorized changes to critical system files and configurations.

  • Critical file monitoring (/etc/passwd, /etc/shadow)
  • Configuration change alerts
  • Baseline comparison with SHA256

SOX IT general controls evidence

The eBPF monitoring captures security events that map to SOX IT general controls. Evidence is collected continuously so you always have what you need.

Section 302: Corporate Responsibility

Data integrity protection, access control tracking, change management logging, and comprehensive audit trails.

Section 404: Internal Controls

Role-based access monitoring, documented change detection, backup job verification, and continuous systems monitoring.

IT General Controls (ITGC)

Logical access (authentication & authorization), change management (authorized changes only), and computer operations (scheduled jobs, backups).

Reports & evidence

Generate compliance-ready reports from security events and evidence captured by your eBPF-monitored CDE hosts. Compliance summary, security event logs, access audit trails, and attestation reports - weekly, daily, or quarterly.

Ready to get started?

Install one agent. Get security monitoring, infrastructure alerts, and on-call management - all included, every plan.