Wraith inspects untrusted processes and can optionally interrupt them. Treat the sensor, its trust ranges and its event destination as part of your security boundary.
Do not disclose an unpatched bypass, memory-safety issue or destructive enforcement bug in a public issue. Use the repository's private vulnerability reporting page if enabled. If unavailable, request a private reporting channel from the maintainer without including exploit details. No response-time or bounty guarantee is offered.
Include the affected revision, Linux kernel, minimal safe reproducer, expected behavior, actual behavior and proposed regression. Do not send secrets or live customer data. Only test systems you own or are authorized to assess.
This is a pre-1.0 Linux x86-64 project; security fixes target the current main branch. There is no LTS branch or enterprise support commitment. Read the threat model and operator guide.
Observe-only is the default. A CRITICAL verdict is a policy decision, not forensic proof. Use enforcement only after validating a representative legitimate workload. Do not run with unrestricted root privileges merely for convenience; attaching requires ownership, applicable Yama permission, or appropriately scoped tracing capabilities. Store JSONL evidence with permissions suitable for process metadata.