ebpf security monitoring · one agent
One agent installs in about a minute and watches your servers from inside the kernel: intrusions, SSH logins, rootkits, crypto miners, file changes. AI reads every event and pages you only when it matters.
Included with every agent-based host on Professional and Business.
Free plan · no card · commercial use allowed
Root SSH login from 203.0.113.7
AI:Source IP is on 2 threat feeds. Nobody on this team logs in from that network, and it is 02:17 on this host. Paging on-call.
the problem
outage
The load balancer kept returning 200 while checkout was broken behind it. The uptime ping was green the whole time. The customer was not.
intrusion
A crypto miner ran politely at 60% CPU for five weeks. Uptime never blinked. The first alert was an invoice, and the second was working out how they got in.
breach
The SSH key added to authorized_keys in March surfaced in an audit in June. auth.log had it the whole time. Nobody was reading auth.log. Nobody ever is.
Three different stories, one failure: nothing was watching from inside the box. A ping from outside can tell you the site answered. It cannot tell you who logged in, what changed, or what is quietly eating the CPU.
the fix, in ten minutes
No demo to book, no sales call. This is the actual first-run experience, end to end.
step 1
Add a server in the dashboard and it generates the install line for you:
curl -sSL 'https://app.alertkick.com/...' | sh step 2
Within about 30 seconds the host appears: CPU, memory, disk, processes, containers, and kernel-level security events. No config written.
step 3
SSH into the box and watch your own login arrive as a security event, explained in plain English. That is the product, working before your coffee cools.
The SSH login you just made, explained and delivered where your team already works. From there it follows your on-call roster and escalation policy until somebody acknowledges it.
what one agent replaces
Every plan includes all of it - these are capabilities, not add-ons.
74 rules · 45 ATT&CK techniques
eBPF sees every SSH session, spawned process, opened port, and changed file - and AI explains each one in plain English.
humans · pipelines · ai agents
Every session, command, and file change attributed at the kernel. SSH locks outside maintenance windows.
pci dss 4.0 · sox
Security events map to controls automatically and reports generate on demand. No pre-audit screenshot hunt.
http · tcp · dns · ssl · domains
Checks from multiple regions, response-time tracking, and SSL and domain expiry warnings weeks before the deadline.
one curl per cron job
Add one line to any script. If the ping stops arriving on schedule, you get paged - instead of finding out three weeks later.
rosters · escalation · mobile app
Rotations, overrides, and escalation chains that keep climbing until someone acknowledges - with a mobile app to ack from bed.
the part nobody else covers
CI pipelines and AI agents now SSH into production, edit configs, and run deploys. In the auth log they look exactly like you. AlertKick gives every change - human or machine - the same three checks:
attributed
Who did it - which human, which pipeline, which agent - captured at the kernel, not guessed from a shared deploy user.
authorized
Was it supposed to happen now? Maintenance windows lock SSH on the host outside approved times - for everyone.
verified
Did what changed match what was declared? File changes diffed against the plan and scanned before the window closes.
go deeper
Everything above is one agent. Here is what the security side actually looks like in the product. For the kernel technology underneath it, read what eBPF actually is.
Event stream, container shell detection, rootkit checks, file integrity monitoring - with screenshots.
Every detection rule, mapped to the technique it covers. Published in full, not summarised.
Uptime, heartbeats, on-call rosters, escalation, compliance, and the MCP server for AI tools.
pricing
Per-seat security tools charge you for every engineer you add. AlertKick's bill tracks your infrastructure, and no plan charges per seat.
free
£0
5 monitors and 5 heartbeats at 5-minute checks, one roster, one escalation policy, and alerts to mobile push, email, Slack, and Telegram. Commercial use allowed.
professional
£39/mo
5 agent-based hosts with eBPF security included, 10 monitors and 10 heartbeats at 1-minute intervals, 30-day retention, unlimited rosters and escalation policies.
business
£149/mo
25 hosts, 50 monitors and 50 heartbeats, 90-day retention, plus compliance evidence and reports for PCI DSS and SOX.
Install the agent on a test host, SSH in, and watch your own login arrive - explained - before your coffee cools. If it earns your trust, roll it out.
Start freefree plan · no card · commercial use allowed