listen.dev provides runtime security monitoring for GitHub Actions, utilizing eBPF technology to gain visibility and control over third-party code in CI environments. This approach helps teams detect and block malicious activity, preventing supply chain attacks and reducing the risk of breaches before they impact production.
Funding
$8.5M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.


Founders
Product
Problem
Modern development pipelines rely heavily on third-party code within CI/CD environments, creating a significant attack surface. Traditional static analysis tools often fail to detect malicious code injected during builds, leaving organizations vulnerable to supply chain attacks and data breaches.
Solution
Garnet provides runtime security monitoring for CI/CD pipelines, offering visibility and control over third-party code execution. By leveraging eBPF technology, Garnet monitors network connections, file access, and process behaviors to establish behavioral baselines and detect anomalies in real time. The platform identifies and blocks malicious activities such as cryptomining, data exfiltration, and unauthorized file tampering, preventing supply chain attacks before they impact production. Actionable alerts are delivered directly to existing toolchains, enabling rapid response and minimizing the mean time to detection (MTTD).
Target Audience
Garnet targets security experts, engineering leaders, and DevOps teams seeking to secure their CI/CD pipelines and protect against supply chain attacks.
Features
- Runtime monitoring of network, file, and process behaviors using eBPF for kernel-level visibility
- Behavioral baselining to automatically establish normal activity patterns for each build
- Real-time threat detection and blocking of malicious activities like cryptomining and data exfiltration
- Integration with existing toolchains (e.g., Slack, SIEM) for actionable alerts and incident response
- Lightweight architecture with minimal performance impact on build times
- Universal compatibility with any Linux environment in the DevOps pipeline
- Out-of-the-box detections and threat intelligence for instant protection