Deft-Intruder
Real-time malware detection daemon for Linux
Details
- External ID
- 46046004
- Source
- HN
- Company
- —
- Product
- Deft-Intruder
- Website domain
- github.com
- Launched
- Nov. 25, 2025
- Cohort
- —
- Upvotes
- 6
- Upvotes percentile
- 0.27074235807860264
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
I built an open-source malware detection daemon that monitors all running processes in real-time using ML + heuristics. No kernel modules or eBPF required.Key points:- Polls /proc for new processes (works on any Linux kernel 2.6+)- Random Forest model trained on EMBER 2018 dataset (2.3M samples)- Heuristic rules for crypto miners, ransomware, rootkits- ~20MB RAM, <1% CPU, sub-millisecond scan latency- Pure C, zero runtime dependencies- Model embedded directly in binary (50KB)Why I built this: Existing solutions either require modern kernels (eBPF) or are heavy/proprietary. I wanted something lightweight that works everywhere - servers, containers, old distros.Detection approach: Extract features from executables (entropy, imports, sections), run ML prediction, apply heuristic rules, combine scores. If above threshold, kill the process.Happy to discuss implementation details or Linux security in general.
Enrichment
- Theme
- security exploits and system hacking tools
- Vertical
- Security
- Function
- Observability & eval
- Audience
- B2B
- AI stance
- AI feature
- Project type
- Commercial product
- Normalized one-liner
- real-time malware detection for linux
- Manually corrected
- False
Could you build this?
Partial Creating a basic daemon that inspects /proc and queries a pre-trained scikit-learn model is straightforward, but building an efficient, evasion-resistant security daemon without missing short-lived processes requires systems security depth.
What it would actually take: The system requires a background daemon written in Rust, Go, or C that captures process lifecycles via `/proc` or Netlink process connectors, extracts static/dynamic binary attributes, and evaluates them with a compiled random forest model (such as Treelite or ONNX Runtime). The difficult parts are avoiding time-of-check to time-of-use (TOCTOU) race conditions on transient malicious processes and minimizing CPU overhead without kernel modules. Requires expertise in Linux systems programming, binary analysis, and security engineering.
Discussion
No comments on this launch.
Competitors
Other products that read as similar to this one — 134 launches clear the similarity bar, closest 8 shown.
Attention rank: #104 of 135 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 16 days after the earliest competitor.
- kernwatch · github · 2026-09-11 · 29 upvotes · similarity 0.51
- netprobe-ir · github · 2026-09-12 · 7 upvotes · similarity 0.46
- Local-first firmware analyzer using WebAssembly · hn · 2026-03-10 · 8 upvotes · similarity 0.45
- MalwareAnalyzer: Static scanning, real detonation, an interactive live VM, and a threat graph you can pivot through · yc · 2026-08-31 · 2 upvotes · similarity 0.45
- Linnix · hn · 2025-11-11 · 21 upvotes · similarity 0.44
- expoCiber-tools · github · 2026-09-25 · 9 upvotes · similarity 0.44
- BDB-Guardian · github · 2026-09-20 · 11 upvotes · similarity 0.43
- Cerberus · hn · 2025-12-20 · 12 upvotes · similarity 0.42
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a observability & eval tool for Media & entertainment yet.