Cerberus
Real-time network monitor with eBPF
Details
- External ID
- 46338219
- Source
- HN
- Company
- —
- Product
- Cerberus
- Website domain
- github.com
- Launched
- Dec. 20, 2025
- Cohort
- —
- Upvotes
- 12
- Upvotes percentile
- 0.5562977099236641
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
Hi HN! I'm Mo, a platform engineer at Deltaflare working on critical infrastructure protection.I built Cerberus because traditional packet capture tools (tcpdump, Wireshark) have too much overhead for production CNI environments. eBPF lets us filter and classify packets at the kernel level with near-zero performance impact.Some interesting challenges: - eBPF verifier is strict - every memory access needs bounds checking - Limited to 32 bytes of L7 payload (tradeoff between inspection depth and overhead) - TC vs XDP decision (chose TC for compatibility)Looking for contributors, especially on: - Redis backend for distributed deployments - Prometheus metrics export - Anomaly detectionHappy to answer questions!
Enrichment
- Theme
- proxy, dns, and networking tools
- Vertical
- Horizontal
- Function
- Observability & eval
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- network monitoring with ebpf
- Manually corrected
- False
Could you build this?
No Real-time kernel-level packet inspection requires deep Linux systems programming, eBPF verifier compliance, and specialized networking expertise.
What it would actually take: A production version requires writing C/eBPF programs attached to XDP or TC kernel hooks, communicating with a Go or Rust userspace daemon via eBPF ring buffers. The primary challenges involve adhering to strict kernel verifier constraints, avoiding performance degradation at high packet rates, and maintaining compatibility across varied Kubernetes CNI network plugins.
Discussion
6 comments analyzed.
Competitors mentioned: Sysdig/csysdig, tcpdump, Wireshark
Concerns raised: eBPF verifier constraints complexity, Slower iteration cycle (compile-load-verify), Limited L7 inspection intentionally
Competitors
Other products that read as similar to this one — 80 launches clear the similarity bar, closest 8 shown.
Attention rank: #43 of 81 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 51 days after the earliest competitor.
- Linnix · hn · 2025-11-11 · 21 upvotes · similarity 0.57
- Dsnitch · hn · 2026-09-06 · 5 upvotes · similarity 0.54
- skyline-speeder · github · 2026-09-18 · 95 upvotes · similarity 0.51
- CargoWall · hn · 2026-03-31 · 14 upvotes · similarity 0.46
- BPU · hn · 2026-02-01 · 11 upvotes · similarity 0.46
- AIOStack · hn · 2026-01-14 · 9 upvotes · similarity 0.44
- Live, system-wide USB transfer sniffer in eBPF · hn · 2026-05-31 · 9 upvotes · similarity 0.44
- Netfence · hn · 2026-01-25 · 58 upvotes · similarity 0.43
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a observability & eval tool for Media & entertainment yet.