Skip to the content.

Security Operations

Deployment controls

Required monitoring

Alert on:

Reject kernel evidence for sessions whose final kernel_telemetry_complete value is false. Do not downgrade queue loss to a normal operational warning.

Evidence limitations

The local hash chain detects record modification, insertion, deletion, and reordering inside retained segments. It cannot prevent deletion of all logs, collector replacement, or generation of a new internally consistent log by a local administrator.

Anchor chain heads and sequence numbers remotely during the session when the events are used as security evidence.

Vulnerability reporting

Use a private security advisory for memory corruption, invalid IRQL, unload races, IOCTL validation bypass, unauthorized device access, or signing-material exposure.

Do not attach kernel dumps, private paths, credentials, or user data to public issues or discussions.