Linux · open source agent

Linux endpoint security. One agent.

Everything your Linux machines need — supply-chain detection, threat scanning, vulnerability management, file integrity monitoring, USB device control, and EDR telemetry — in a single lightweight, fast, and powerful open-source agent that works offline.

Install on Linux See capabilities Free tier, no account.
97%of npm's security advisories are malware, not bugs
235,577malicious packages Hound blocks by name
2 msto stop a malicious binary at execve
0.8 msadded to every other program you run
Capabilities

Six layers of endpoint protection.

Each layer handles a different attack surface. Together they cover the full lifecycle — from a malicious dependency entering your lockfile to a compromised binary phoning home.

Supply chain

Dependencies that are malware

Typosquats, slopsquats, install-script payloads, pickle opcodes, prompt injection in AI config files, and MCP server audits. Reads your lockfile and catches what will be installed before the install script ever runs. 235,577 known-malicious indicators across npm, PyPI, RubyGems, crates.io, Go and Packagist.

Execution

Stopped at launch, not flagged after

Most tools tell you about malware that already ran. Hound denies the execve itself, in about two milliseconds, built on fanotify. A watchdog fails the gate open — a bug in your security agent must never be the thing that freezes your machine.

VulnerabilitiesNew

CVEs in what you already have installed

Scans installed packages for known vulnerabilities and sorts them by what actually matters: exploitability scores from EPSS and whether they appear on the CISA Known Exploited Vulnerabilities catalog. Not a wall of CVEs — a prioritized list of what to fix first.

File integrityNew

What changed, and whether it should have

Hash baselining and change detection for critical files. Maps changes to PCI-DSS and NIST 800-53 controls, so compliance reports write themselves. If something modified /etc/shadow or a systemd unit outside a known deployment, you know about it.

USB controlNew

Deny by default, allow by device

USB mass storage and HID devices are blocked until you approve them. Per-device policies, BadUSB protection, and audit logging. The attack where someone drops a USB stick in the parking lot stops working.

EDR telemetryNew · Team

See what your fleet is doing

Process trees, network connections, DNS queries, and behavioral alerts across every machine in your fleet. When something goes wrong, you have the forensic trail to understand what happened and how far it spread.

See the full feature list across all tiers →

Why Hound

Built for Linux. Not ported to it.

The incumbent tools were designed for Windows desktops and adapted to Linux as an afterthought. Hound is the opposite — Linux-native from day one.

Linux-native

Uses fanotify instead of a kernel module. No driver to load, no kernel to taint, no risk of a bad update panicking your machine. Remember CrowdStrike's global outage in 2024? That cannot happen here.

Lightweight and fast

The execution gate adds 0.8 ms to a program launch and sustains 4,000+ executions per second. On a server running 21 containers, arming Hound did not move request latency or load average. Security that stays out of the way.

Powerful

Six security layers in one agent — supply-chain detection, threat scanning, vulnerability management, file integrity monitoring, USB device control, and EDR — with nothing to license separately. Others charge per module; Hound ships everything.

Works offline

No cloud dependency. Definitions ship as signed packs you can mirror locally. Air-gapped, regulated, or just on a plane — Hound keeps working. The only network request it ever makes is fetching definition updates, and you can point that at your own mirror.

Open source

Apache-2.0 and the source is public. You are being asked to run a root daemon that can block execution — you should be able to read it. Definitions are signed with a key whose public half ships in the binary, so anyone can verify what they received.

Fails safe

If the daemon crashes, the kernel releases every pending execution within 500 ms. No freeze, no lockout, no bricked machine. A bug in a security agent must never be worse than the threat it blocks — so that path is tested, not assumed.

Pricing

The agent is free. The feed and the fleet are not.

Everything that runs on your own machine — scanning, quarantine, supply-chain and agent-era checks, vulnerability detection, the MCP server — is free forever, no account and no expiry. What you pay for is the part that costs real money to build and serve.

AnnualSave 20%
Monthly

Community

The developer safety net

$0

Everyone. No account, no telemetry, no expiry.


  • On-demand scanning, CLI and desktop app
  • Recent malicious-package feed — ~5K indicators
  • Full supply-chain heuristics — typosquat, slopsquat, install-script, pickle opcodes, prompt injection, MCP audit
  • Real-time file protection and quarantine vault
  • MCP server for coding assistants
  • Rootkit and persistence checks
  • Vulnerability scanning — CVEs in installed packages, sorted by exploitability (EPSS + CISA KEV)
Install

Apache-2.0. Yours to read and to fork.

Most popular

Pro

The secure workstation

$8 / mo

Billed annually at $96/year.


  • Everything in Community
  • Execution gate — blocks malicious binaries at launch in 2 ms
  • Full malicious-package feed — all 235,577+ indicators, refreshed daily
  • Hound Linux threat pack — miners, backdoors, rootkits, webshells (34 curated YARA rules)
  • File integrity monitoring — hash baselining, change detection, PCI-DSS/NIST compliance tags
  • USB device control — deny-by-default, per-device policies, BadUSB protection
  • Signed incremental definitions
Get Pro

Cancel any time.

Team

The secure organization

$14 / seat / mo

Billed annually at $168/seat/year. No minimum.


  • Everything in Pro, on every machine
  • Central console — fleet dashboard, enrolment, device inventory
  • Policy push — security policies applied across all machines from one place
  • Compliance reports — PCI-DSS, NIST 800-53, HIPAA-ready audit exports
  • EDR telemetry — process trees, network connections, DNS queries, behavioral alerts
  • USB fleet policy — organization-wide device allow/block lists
  • Slack and webhook alerts — threat detections, compliance drift, agent-offline events pushed to your channels Soon
  • Air-gapped definition mirrors
  • Priority support and a named contact
Get Team

Volume pricing available over 25 seats.

Enterprise

Your rules, your infrastructure

Custom

Annual contract. Tailored to your environment.


  • Everything in Team
  • Custom YARA + SIGMA rules — your threat models, maintained for you
  • SSO / SAML — Okta, Azure AD, Google Workspace
  • On-prem console — self-hosted fleet management, your network only
  • SIEM / syslog export — Splunk, Elastic, Datadog, syslog-ng
  • Dedicated support + SLA — named contact, guaranteed response times
  • SOC 2 / ISO 27001 compliance reports
Talk to us

We scope it, you approve it.

For people who code with agents

Your coding assistant can ask Hound before it trusts anything.

You have handed an AI agent the keys to your machine and pointed it at the open internet. Hound ships an MCP server, so Claude, Cursor, VS Code — anything that speaks MCP — can check a repository, a package or a model file before it installs or runs a thing.

~/.config/mcp/servers.json
{
  "mcpServers": {
    "hound": {
      "command": "/usr/bin/hound-mcp"
    }
  }
}

// No npx — nothing fetched at launch.
// No env — no secret handed over.
// No path — no directory granted.
//
// Hound flags all three in other
// people's configs. Ours passes its
// own audit.

Four read-only tools

check_project, check_package, check_file, check_mcp_config. There is no quarantine tool and never will be — an assistant that can be persuaded by the repository it is reading must not be able to make your security agent delete things.

It audits the tools you already trust

Every MCP server in your config runs with your permissions and gets called without asking you. Hound tells you which ones download their code fresh on every launch, and which ones you handed a token.

Install

One command, then it is running.

Ubuntu, Debian and Linux Mint today. The execution gate ships switched off — it needs root and covers your whole filesystem, so turning it on is your decision rather than the installer's.

Debian, Ubuntu, Mint

curl -fsSL https://get.houndav.com | bash

RPM packages (Fedora, RHEL, Rocky) are coming soon.

Questions

What people ask before installing it.

How is Hound different from traditional antivirus?

Hound does scan files and quarantine malware, but that is one layer of six. Traditional antivirus databases are overwhelmingly Windows malware, which is close to irrelevant on a Linux machine. What actually compromises Linux systems is a dependency, a model file, a misconfigured service, or a compromised supply chain — so most of Hound is supply-chain detection, vulnerability management, file integrity monitoring, USB device control, and EDR telemetry. It is an endpoint security platform that includes malware scanning, not a scanner that bolted on extras.

How is Hound different from CrowdStrike?

CrowdStrike was built for Windows and adapted to Linux. It requires a kernel module (which famously caused a global outage in 2024), depends on cloud connectivity, does not offer USB device control on Linux, and cannot do on-demand scanning. Hound is Linux-native from the ground up: it uses fanotify instead of a kernel module, works fully offline, includes USB control, and lets you scan anything from the CLI or desktop app. Hound is lightweight, fast, and purpose-built — with a free tier that has no expiry and no account.

Does Hound slow my machine down?

The execution gate adds about 0.8 milliseconds to a program starting, and sustains over 4,000 executions per second. On a server running 21 containers, 16 Node processes and a web server, arming it did not move request latency or load average. A verdict cache means a program you have already run is answered from memory without re-reading it.

What happens if Hound crashes while it is blocking programs?

Nothing. The gate fails open: a watchdog releases any execution that has not been answered within 500 milliseconds, and if the daemon dies outright the kernel releases everything pending when its descriptor closes. A bug in a security agent must never be able to freeze a machine, so that path is tested rather than assumed.

Is Hound open source?

The agent is Apache-2.0 and the source is public. You are being asked to run a root daemon that can block execution, so you should be able to read it. Definitions are signed with a key whose public half is compiled into the binary, so anyone can verify that the definitions they received are the ones that were published. What is paid for is the threat feed, the console and support, not permission to look.

Does Hound phone home?

No telemetry by default, and it can run fully offline with definitions imported from a file, which is how it works in air-gapped and regulated environments. The only network request it makes is fetching signed definition packs, and you can point that at your own mirror.

What about Windows and macOS?

macOS support is coming. Windows is not on the roadmap. The Linux security market is underserved because the incumbent tools were designed for Windows and ported over — Hound is the opposite: built for Linux first, because that is where the machines that matter most are running. macOS shares enough of the Unix model that it is a natural next step.

Open source

You are installing a root daemon that can block execution.

So you should be able to read it. The agent is Apache-2.0 and the definitions are signed with a key whose public half is compiled into the binary — anyone can verify that what they received is what we published. What you pay for is the threat feed, the console and support, not permission to look.