Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Deft-Intruder

Real-time malware detection daemon for Linux

Details

External ID
46046004
Source
HN
Company
—
Product
Deft-Intruder
Website domain
github.com
Launched
Nov. 25, 2025
Cohort
—
Upvotes
6
Upvotes percentile
0.27074235807860264
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

I built an open-source malware detection daemon that monitors all running processes in real-time using ML + heuristics. No kernel modules or eBPF required.Key points:- Polls /proc for new processes (works on any Linux kernel 2.6+)- Random Forest model trained on EMBER 2018 dataset (2.3M samples)- Heuristic rules for crypto miners, ransomware, rootkits- ~20MB RAM, <1% CPU, sub-millisecond scan latency- Pure C, zero runtime dependencies- Model embedded directly in binary (50KB)Why I built this: Existing solutions either require modern kernels (eBPF) or are heavy/proprietary. I wanted something lightweight that works everywhere - servers, containers, old distros.Detection approach: Extract features from executables (entropy, imports, sections), run ML prediction, apply heuristic rules, combine scores. If above threshold, kill the process.Happy to discuss implementation details or Linux security in general.

Enrichment

Theme
security exploits and system hacking tools
Vertical
Security
Function
Observability & eval
Audience
B2B
AI stance
AI feature
Project type
Commercial product
Normalized one-liner
real-time malware detection for linux
Manually corrected
False

Could you build this?

Partial Creating a basic daemon that inspects /proc and queries a pre-trained scikit-learn model is straightforward, but building an efficient, evasion-resistant security daemon without missing short-lived processes requires systems security depth.

What it would actually take: The system requires a background daemon written in Rust, Go, or C that captures process lifecycles via `/proc` or Netlink process connectors, extracts static/dynamic binary attributes, and evaluates them with a compiled random forest model (such as Treelite or ONNX Runtime). The difficult parts are avoiding time-of-check to time-of-use (TOCTOU) race conditions on transient malicious processes and minimizing CPU overhead without kernel modules. Requires expertise in Linux systems programming, binary analysis, and security engineering.

Discussion

No comments on this launch.

Competitors

Other products that read as similar to this one — 134 launches clear the similarity bar, closest 8 shown.

Attention rank: #104 of 135 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 16 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a observability & eval tool for Media & entertainment yet.