LTFI-Aegis · security platform for Linux fleets · v0.3.4

One agent on every node. One console for the whole estate.

LTFI-Aegis pairs a single signed eBPF agent — kernel-deep detection and active prevention on each Linux node — with a console that turns the whole fleet into one operations picture: attack surface, layer-7 traffic, SOC, threat hunting, exposure, posture, and compliance.

Included with Kief Studio managed hosting · Per-node & OEM/datacenter licensing · Air-gap friendly · Signature-verified releases

LTFI-Aegis console dashboard — fleet intelligence: incidents by severity, open incidents by module, top threats, fleet exposure and security posture, with a live 14-node fleet rail.
The LTFI-Aegis console — live fleet intelligence. Shown with synthetic demo data.
6→1
legacy node agents replaced by one signed binary
1 console
fleet, surface, traffic, SOC, hunting & compliance
1.37M
botnet requests weathered, zero host compromise
v0.3.4
signed, fleet-wide self-update

What it is

A platform, not a point tool — the sensor and the brain

Most security stacks are a sensor you buy and a SIEM you rent, glued together by you. LTFI-Aegis ships both halves as one product: the agent that sees and stops things on the node, and the console that correlates, scores, and lets you act across every node at once.

The agent — on every node

Kernel-deep, in one signed binary

A single ~4.7 MB eBPF agent replaces the six-tool patchwork — log shipping, host metrics, syscall audit, IP banning, file-integrity, blocklisting — and adds active prevention those tools never had.

  • Anti-ransomware behavior blocking in the kernel (eBPF LSM)
  • File-integrity tamper protection and self-protection
  • Per-node capability grants, fail-closed by default
  • Signature-verified self-update (minisign + SBOM)
The console — for the whole fleet

One operations picture

Every agent reports to one console. Instead of per-box guesswork, you get fleet posture, external exposure, live traffic, incidents, and compliance evidence in a single pane — with the controls to respond.

  • Live fleet health, incidents, and exposure scoring
  • External attack surface and layer-7 traffic analytics
  • SOC operations, threat hunting, and case management
  • Posture, compliance evidence, and a unified asset registry

How it works

From bare node to fleet-wide visibility

No rip-and-replace and no SIEM integration project. Deploy the agent, let it learn, promote to enforce, and operate the whole estate from the console.

Deploy the agent

One signed static binary and a config block per node. No kernel modules, no out-of-tree drivers. Telemetry starts flowing immediately.

Learn the baseline

Each node runs in learn mode for 48–72 hours, modeling what normal looks like before anything is enforced.

Promote to enforce

Flip to enforce. Active prevention is on at the kernel; the console shows enforce/learn state across the fleet.

Operate from the console

Watch posture, hunt, triage incidents, score exposure, and produce compliance evidence — across every node, in one place.

Capabilities

Everything the fleet needs, in one console

Each capability below is part of the same platform, driven by the same agent telemetry — no extra sensors, no extra vendors. Here's what each one is, how it works, and who it's for.

Fleet command

See and defend every node

enforce / learn · module health · live telemetry

The dashboard is mission control: incident severity trends, open incidents by module, top threats, fleet exposure, and a live rail of every node and its mode.

LTFI-Aegis fleet view listing every node with mode, posture score and module health.
What it is

A real-time command view of the whole fleet — every node's mode (enforce/learn), posture score, module health, and the incidents and threats that need attention now.

How it works

Each agent streams health and behavioral telemetry to the console, which rolls it up into fleet-wide posture and drill-downs to any single node's services, vulnerabilities, and self-test results.

Who it's for

Platform and infrastructure teams who need one screen to answer "is the fleet healthy, and what's on fire?" without SSH-ing box to box.

External attack surface

Know what the internet can see

EASM · nuclei findings · TLS · exposed secrets

Continuous external scanning of your domains and endpoints — security and SEO scores, nuclei findings by severity, exposed secrets, subdomains, TLS posture, and a scan pipeline.

LTFI-Aegis External Attack Surface dashboard — active targets, average security and SEO scores, nuclei findings, exposed secrets, subdomains, TLS coverage and score trend.
What it is

External Attack Surface Management built into the platform — the outside-in view of every web property you run, scored and tracked over time.

How it works

A scan pipeline enumerates targets and subdomains, runs nuclei templates, checks TLS and security headers, and flags exposed secrets — feeding findings and trends straight into the console.

Who it's for

Teams responsible for public-facing assets — agencies, hosts, and security owners who need to catch exposure before an attacker does.

Layer-7 traffic analytics

Tell humans, bots, AI and attackers apart

humans · bots · AI crawlers · attackers · blocked@edge

Real-time L7 analytics across the fleet — request volume and actor mix, geography, and a security view that shows exactly what was blocked at the edge and what got through.

LTFI-Aegis traffic security view — disposition mix, findings by severity, attacker IPs, and a findings table showing credential-stuffing and probes blocked at the edge.
What it is

A layer-7 traffic lens that classifies every request — verified human, bot, AI crawler, automation, or attacker — and shows the security disposition of each.

How it works

Edge and agent telemetry are classified and aggregated into live timeseries, geography, and a findings feed where each attack shows its result: blocked at edge, deflected, or served.

Who it's for

Operators defending public sites and APIs who need to prove their edge is absorbing abuse — and quantify the human traffic underneath the noise.

SOC & incident response

Triage and respond from one queue

MTTD/MTTR · cases · playbooks · disposition

A working SOC view: MTTD/MTTR and SLA metrics, a live alert queue, analyst workload, disposition breakdown, and incidents you can drive from open to resolved with a timeline and response actions.

LTFI-Aegis SOC view — MTTD/MTTR/SLA metrics, alert queue with ages and modules, activity feed, opened vs closed trend, disposition donut and analyst workload.
What it is

Security operations and incident response in the console — alert queue, case management, response playbooks, and the metrics that tell you how fast you detect and resolve.

How it works

Agent and module detections become alerts and incidents; analysts claim, escalate, run playbooks, and disposition them, while the console tracks MTTD, MTTR, SLA compliance and workload.

Who it's for

MSSPs and in-house security teams who want a SOC workflow tied directly to the same agents enforcing on the fleet — not a disconnected ticketing tool.

Threat hunting

Hunt the fleet's event logs

presets · custom queries · CSV/JSON export

Query fleet-wide event logs with one-click presets or custom filters — cryptoshield blocks, first-seen egress, auth failures, privilege escalation — with severity and module breakdowns and export.

LTFI-Aegis threat hunting — preset hunts and a result set of 38 events with severity and module distribution charts and CSV/JSON export.
What it is

Interactive threat hunting over the telemetry every agent produces — presets for common hunts plus custom queries by node, module and severity.

How it works

Hunts run against the fleet's event store and return matching events with severity/module distributions; results export to CSV or JSON for reporting or escalation into a case.

Who it's for

Analysts and responders who need to ask the fleet a question — "show me first-seen egress in the last 7 days" — and get an answer in seconds.

Exposure, posture & compliance

Score risk and prove control

exposure score · CIS/SOC2 · evidence

A composite exposure score per node from vulnerabilities, compliance, posture, surface and behavior — plus posture by domain and per-framework compliance status you can hand to an auditor.

LTFI-Aegis exposure view — fleet exposure scoring with contributing factors across vulnerabilities, compliance, posture, surface and behavior.
What it is

Risk made measurable: an exposure score that combines vulnerabilities, compliance failures, posture, attack surface and behavioral anomalies into one number per node and for the fleet.

How it works

The console weighs each factor from agent and scan data, trends it over time, and maps control status to SOC 2, NIST 800-171, CMMC, PCI and HIPAA evidence.

Who it's for

Leaders and compliance owners in regulated industries who need to show risk going down and produce audit evidence without a tool-stitching project.

Asset registry

One inventory of everything you run

hosts · services · domains · endpoints · access zones

A unified registry that merges fleet hosts and services with externally-discovered domains and endpoints — every asset classified by access zone, from public to internal.

LTFI-Aegis asset registry — unified inventory of hosts, services, domains and endpoints classified by access zone with type and severity breakdowns.
What it is

A single source of truth for assets — hosts, services, domains and endpoint findings — with access-zone classification so you know what's public, meshed, or internal.

How it works

Fleet collectors and the EASM pipeline feed one registry, linking domains to their endpoints and nodes, so external exposure and internal inventory live in the same place.

Who it's for

Anyone who's ever asked "what do we actually run, and which of it is exposed?" — security, ops, and compliance, working from the same list.

Drive it yourself

The whole platform, on synthetic data

No form wall, no sales call. Open the live console and click through fleet defense, attack surface, traffic, SOC, hunting, exposure and the asset registry — running entirely on fake data.

Drive the live demo →

Who it's for

Built for the people who run the infrastructure

LTFI-Aegis is the security layer included with Kief Studio managed hosting — and a platform datacenter operators, MSPs and OEMs can license to run on their own estate.

Managed-hosting clients

Protection that comes with the service

If Kief Studio runs your infrastructure, Aegis is already there — every node defended, the whole estate visible, no extra product to buy or operate.

  • Agent + console included with hosting
  • We run it in enforce mode for you
  • Compliance evidence on tap
MSPs & MSSPs

One platform across every client

Run a real SOC workflow over a multi-tenant fleet — fleet defense, hunting, and case management on the same agents that enforce, with per-client visibility.

  • Multi-tenant fleet and client views
  • SOC, hunting and incident response built in
  • Per-node licensing that scales with you
Datacenters & OEMs

License or embed the platform

Operators and product teams can license Aegis per node or embed the agent in their own offering — a signed, self-updating supply chain you can stand behind.

  • Per-node and OEM/embedding licensing
  • Air-gap friendly, signature-verified releases
  • Built and supported by the team that runs it

Field-proven

Built and proven in production

LTFI-Aegis isn't a lab project. It runs in enforce mode across Kief Studio's managed production fleet, protecting real client workloads every day.

During a sustained campaign against a managed-hosting client — roughly 1.37 million inbound requests from a residential-proxy botnet — Aegis' host-runtime integrity monitoring and behavioral telemetry confirmed, with evidence, that nothing executed on the box while edge controls absorbed the volume. Inbound enumeration, never a compromise.

— Anonymized incident. The traffic was external, from residential proxies; the host was the target, never the source, and was never breached.

Who builds it

Engineered by the team that runs it

LTFI-Aegis is part of the LTFI ecosystem, developed and operated by Kief Studio LLC — a family-owned Massachusetts technology firm founded in 2022. We don't resell security software; we build the platform we run, and we run it in production.

Brian Gagne

Co-founder & CTO

Twenty years of technology and infrastructure engineering. Writes the Rust and eBPF behind the agent and the console behind the fleet — and operates the production estate it protects.

  • Cisco Certified Ethical Hacker (CCEH)
  • Perplexity AI Business Fellow
  • Author, “The Crossroads of AI Integration”

Amelia Gagne

Co-founder & CEO

Full-stack developer and operator. Leads product and the business behind LTFI, and sits on the board of an enterprise cybersecurity platform.

  • Perplexity AI Business Fellow
  • Full-stack engineering (Rust, Python, React)
  • Board member, enterprise security platform

Questions, answered

LTFI-Aegis FAQ

What is LTFI-Aegis?
A security platform for Linux fleets with two parts: a single signed eBPF agent on every node for kernel-level detection and active prevention, and a console that unifies fleet defense, external attack surface, layer-7 traffic, SOC operations, threat hunting, exposure, posture, compliance, and a full asset registry.
Is it a product I buy, or part of hosting?
Both. It's included with Kief Studio managed hosting, so managed clients get the agent and console as part of the service. Datacenter operators, MSPs and OEMs can also license it per node or embed the agent in their own offering.
Can I see the console first?
Yes — there's a live, drivable demo of the full console at ltfi-aegis.kief.studio/demo, running entirely on synthetic data. Click through every view before you talk to anyone.
What does the agent replace on each node?
The common per-node stack — log shipping, host metrics, syscall auditing, IP banning, file-integrity monitoring, and known-bad blocklisting (~110 MB of resident agents) — collapses into one ~4.7 MB signed binary, plus kernel-level prevention those tools don't provide.
How is it deployed?
Drop the binary and a config block on each node. It runs in learn mode for 48–72 hours to build a baseline, then you promote it to enforce. No kernel modules, no out-of-tree drivers, and telemetry reaches the console immediately.
Does it help with compliance?
Yes. Controls map to SOC 2, NIST 800-171, CMMC, PCI, and HIPAA, and the console tracks per-node compliance status — one platform producing evidence across frameworks.
Who builds and supports it?
Kief Studio LLC, a Massachusetts firm founded in 2022 by Amelia Gagne (CEO) and Brian Gagne (CTO, a Cisco Certified Ethical Hacker). It's part of the LTFI ecosystem and runs across Kief Studio's managed fleet.

Start with a slice

Pilot LTFI-Aegis on a handful of your nodes

Tell us a little about your fleet and we'll scope a pilot — no commitment to the whole estate on day one. Prefer to look first? Drive the live demo →

  • A signed agent and config you can deploy to a test slice
  • Console access to watch that slice come online
  • Per-node licensing and OEM-embedding options for partners
  • Compliance-control mapping for your audit frameworks

What happens next: we reply within one business day to scope your pilot. No sales script.

We reply within one business day · [email protected]

Pilot LTFI-Aegis on your fleet