---
title: "Chapter 07: Runtime Kernel Syscall Enforcement with Cilium Tetragon | TinyCTO Zero-Trust Canon"
description: "Real-time in-kernel attack detection and autonomous prevention. Authoring Tetragon TracingPolicies, inspecting `sys_execve` arguments, preventing container breakouts, and triggering sub-millisecond in-kernel SIGKILL."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_manuals_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/manuals/07-runtime-kernel-threat-detection-tetragon"
locale: "en"
---

# Chapter 07: Runtime Kernel Syscall Enforcement with Cilium Tetragon

> **Canonical Zero-Trust Engineering Field Manual**
> **Read Time**: 21 min read | **Maturity**: OPTIMAL | **NIST SP 800-207**: NIST SP 800-207 Tenet 5 & 7

## Executive Summary

Real-time in-kernel attack detection and autonomous prevention. Authoring Tetragon TracingPolicies, inspecting `sys_execve` arguments, preventing container breakouts, and triggering sub-millisecond in-kernel SIGKILL.

## Chapter Content

# Runtime Kernel Syscall Enforcement with Cilium Tetragon

## The Blindness of User-Space Security
Traditional runtime security tools poll Linux system logs, parse auditd streams, or inspect user-space process trees. These approaches suffer from high latency (seconds to minutes) and are easily circumvented by modern kernel exploits, namespace escapes, or log tampering.

## In-Kernel Enforcement via eBPF
Cilium Tetragon hooks directly into kernel system calls, tracepoints, and Linux Security Module (LSM) hooks. It evaluates security policies **in-kernel before the system call returns**. If an adversary attempts an unauthorized action, Tetragon executes an instantaneous in-kernel process termination (`SIGKILL`), neutralizing the threat in microseconds.

## Defense Scenarios
1. **Container Breakout Prevention:** Block processes from executing `sys_setns` or modifying host namespaces.
2. **Reverse Shell Neutralization:** Detect execution of shells (`/bin/sh`, `/bin/bash`) spawned by web servers (nginx, nodejs, python) and immediately kill the child process.
3. **Privilege Escalation Interception:** Detect unauthorized transitions to root UID (0).

```yaml
apiVersion: cilium.io/v1alpha1
kind: TracingPolicy
metadata:
  name: block-reverse-shell-in-web
  namespace: production
spec:
  kprobes:
    - call: "sys_execve"
      syscall: true
      args:
        - index: 0
          type: "string"
      selectors:
        - matchArgs:
            - index: 0
              operator: "Prefix"
              values:
                - "/bin/sh"
                - "/bin/bash"
                - "/usr/bin/python"
          matchNamespaces:
            - "production"
          matchActions:
            - action: Sigkill
```


### Canonical Links & Cross References

- **Manuals Library**: https://tinycto.tv/zero-trust/manuals
- **18 Reference Architectures**: https://tinycto.tv/zero-trust/architectures
- **Posture Assessor Wizard**: https://tinycto.tv/zero-trust/wizard
- **Security Tooling Matrix**: https://tinycto.tv/zero-trust/matrix

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Chapter 07: Runtime Kernel Syscall Enforcement with Cilium Tetragon | TinyCTO Zero-Trust Canon",
  "description": "Real-time in-kernel attack detection and autonomous prevention. Authoring Tetragon TracingPolicies, inspecting `sys_execve` arguments, preventing container breakouts, and triggering sub-millisecond in-kernel SIGKILL.",
  "url": "https://tinycto.tv/zero-trust/manuals/07-runtime-kernel-threat-detection-tetragon",
  "inLanguage": "en"
}
```
