โ–ฎโ–ฎ SahmEDR

Kernel-level EDR for your Linux fleet, as a service

eBPF telemetry, MITRE ATT&CK-mapped detection, automated response and host isolation. Local-first by design โ€” your endpoints keep protecting themselves even when the internet is gone.

๐Ÿ‘

See everything

eBPF exec / file / network / ptrace telemetry with container & Kubernetes lineage โ€” plus fanotify, netlink and proc fallbacks for any kernel.

๐ŸŽฏ

Detect what matters

Path, chain, anomaly and sequence rules, Sigma import, YARA, and five threat-intel feeds. Fully offline-capable detection engine.

๐Ÿ›ก

Respond automatically

Kill, quarantine, and nftables-isolate at policy severity โ€” with a pre-execution gate that blocks known-malicious binaries before they run.

๐Ÿ”Œ

Enroll in one command

sudo sahmedr login, approve the code in this portal, done. No config files to hand-edit, no shared secrets in the fleet.

๐Ÿง 

AI triage, metered

Optional LLM enrichment through our gateway โ€” server-side keys, atomic quotas, and per-request usage you can see. Core detection never depends on it.

๐Ÿ“œ

Fail safe, never destructive

Expired payment never deletes anything: agents drop to a documented restricted mode and recover automatically the moment billing is fixed.

Protect a host in three steps

Install

Grab the signed .deb from downloads: sudo apt install ./sahmedr_*.deb

Enroll

sudo sahmedr login โ€” approve the device code here in your browser. Credentials are per-agent and revocable.

Run

sudo systemctl start sahmedr โ€” the agent reports to your fleet, refreshes its authorization lease, and stands guard.