[Part 1] Building Correlic: Capturing Every Action Your AI Agent Tries to Hide
Four failed attempts, one kernel breakthrough, and the real cost of making AI agents transparent
Apr 4, 202619 min read16
![[Part 1] Building Correlic: Capturing Every Action Your AI Agent Tries to Hide](https://cdn.hashnode.com/uploads/covers/69c716e37cf27065106b8c93/b15b685b-3d0d-4c4c-b526-50bc7704ce77.png)
Search for a command to run...

Series
The real engineering story behind building kernel-level security monitoring for AI coding agents — from userspace failures to eBPF breakthroughs, detection engines, behavioral baselines, and an AI investigation system that never hallucinates. Three parts, every wall hit along the way.
Four failed attempts, one kernel breakthrough, and the real cost of making AI agents transparent
![[Part 1] Building Correlic: Capturing Every Action Your AI Agent Tries to Hide](https://cdn.hashnode.com/uploads/covers/69c716e37cf27065106b8c93/b15b685b-3d0d-4c4c-b526-50bc7704ce77.png)
Four failed attempts at teaching a machine what matters — and the baseline system that finally got it right.
![[Part 2] Building Correlic: Your AI Agent Made 70 System Calls Per Second. Here's How I Taught My System Which Ones Matter.](https://cdn.hashnode.com/uploads/covers/69c716e37cf27065106b8c93/73419568-9871-41fb-8095-2f0661c443bd.png)