Bastion Cyber presents GhostShield V3.0 — Endpoint Detection & Response for Linux
Inside the host, your network defenses are blind. Drop the hammer
before the payload
executes.
Once an attacker is executing on the host, your perimeter is behind
the fight. GhostShield decides inside the kernel, at
the moment the action is attempted: a move that violates policy is
refused before it lands, not written up after it has. It is
Surgical Defense — the offending operation is
denied or the process tree is frozen in place, while the rest of the
host keeps serving. What it contains stays inspectable, and every
decision lands in a local audit trail where a later edit is detectable.
And it answers the question that actually decides the purchase:
what happens when the agent is wrong? The fear is not
the malware — it is the endpoint agent killing PID 1’s
database at 3 a.m. over a false positive. GhostShield is built the
other way round: containment is scoped to the offending process tree,
the services you declare are exempt from lethal enforcement, and every
defence that cannot classify an action lets it through rather than
guessing. A Zero-Outage posture is the design goal of
the engine, not a slogan bolted onto it.
- 0.0–0.5%CPU, day to day
- ChainedTamper-evident logs
- 0Cloud dependencies†
- 1Command to operate
† Forensics, detection and logs stay on the
host. The agent opens no outbound connection of its own: it
has no HTTP client compiled into it, and it verifies your licence
offline, against a public key built into the binary. The one exchange
with us happens off the agent — you collect your signed
licence key here, on this site, once, before you install.
Requires Linux kernel 5.8 or newer.
Guided two-step install: kernel preparation first, then the agent.
Runs on modern Linux distributions that provide BPF LSM — cloud,
bare metal or VM. Nothing is sent off the host.
Server requirements. Linux kernel 5.8 or
newer — the engine's event channel is the BPF ring
buffer, introduced in that version. The kernel also needs
BTF (CONFIG_DEBUG_INFO_BTF) and
BPF LSM (CONFIG_BPF_LSM), which is the
default in the generic cloud images of Ubuntu, Debian, RHEL and
derivatives, plus unified cgroup v2 for the
process-freeze containment. The installer checks all four before
writing anything and stops with the reason, leaving no files behind.