Skip to content

Cache Categories

Jibril uses different cache types for different things:

  • Match events to the right process
  • Rebuild activity for each detection
  • Track process and resource links
  • Connect files and network to processes
  • Adjust memory use by cache size

Task Caches

CacheDescription
tasksActive processes (PIDs).
rec-tasksRecently ended processes.
cmdsCommand lines for processes.
argsProcess arguments.
task-refProcess relationships (ancestry, forks).

File Caches

CacheDescription
filesAccessed or watched files.
dirsAccessed directories.
basesBase directories or filenames.
task-fileTask-to-file access mapping.
file-taskFile-to-task access mapping.

Network Caches

CacheDescription
flowsNetwork connections (TCP/UDP).
task-flowProcess-to-network mapping.
flow-taskNetwork-to-process mapping.
flow-refRelated network flows (both sides of TCP).