Technical blog
AI agent security, eBPF, and compliance
Technical articles written by the engineers building H7. No marketing copy — only things we can demonstrate at the kernel layer.
H7 v3.0.7 / v3.0.8: two new detection channels, speculative containment — and a fix we publish instead of hiding
The July releases add Ring-0 privilege-escalation intercept and contract-scoped sensitive-file detection to the public channel list, introduce the Degrade containment dial, and fix a calibration-bootstrap gap in the network-egress detector. Here is exactly what shipped, and exactly what is not validated yet.
Read article →
Detecting Living-off-the-Land attacks at the kernel layer with eBPF
LOTL attacks use only legitimate OS syscalls — already whitelisted by EDR. Here is why behavioral sequence analysis at the eBPF layer catches them when everything else misses.
Read article →
DORA Art. 17 evidence for AI agents: what an auditor actually needs
DORA has been in force since January 2025. Here is a precise mapping of what Art. 17 requires for ICT incident documentation, and how a signed .cal certificate satisfies each requirement.
Read article →