FOR CLOUD SECURITY TEAMS

FIM that self-configures and investigates its own alerts.

Perj's file integrity monitoring discovers critical files on each node and alerts on relevant changes. It reconstructs the process lineage and user identity behind each event, then returns an AI-investigated verdict with affected paths and supporting evidence.

Event chain

Critical
  1. containerd-shim-runc-v2

    Kubernetes container runtime process

  2. EXECVE /bin/sh

    Non-interactive root shell launched outside the normal process lineage

  3. OPEN /root/.ssh/authorized_keys

    SSH public key appended to a policy-significant asset

Root SSH Persistence

Malicious · 98%