October 2, 2026 · 2 min read
Why we don't install a kernel driver
Our agent runs entirely in user space. That gives up some visibility, and we think it's the right trade for a small company. Here's the reasoning, including the part that isn't flattering.
In July 2024, a faulty update to a kernel-level component from one of the largest security vendors in the world took millions of Windows machines offline in a single morning. Airlines grounded flights. Hospitals went to paper.
The machines didn't fail because they were attacked. They failed because the security software itself ran inside the operating system's kernel, the most privileged layer, where a mistake doesn't crash an app. It crashes the computer.
Our agent doesn't run there, and that's a deliberate decision.
What "user space" means
Every operating system separates the kernel, the core that talks to the hardware, from user space, where ordinary programs run. When a program in user space crashes, the system carries on. When code in the kernel crashes, the whole machine goes down, and sometimes it can't start again until someone intervenes by hand.
Scouter runs entirely in user space, on macOS and on Linux. On macOS that's also Apple's own direction: Apple has moved security products away from kernel extensions and onto its Endpoint Security framework, which delivers the same kind of events to software running in user space.
What we give up
It would be dishonest to call this free. A user-space agent:
- Can be interfered with more easily by an attacker who already has administrator rights;
- Doesn't see the earliest moments of the boot process;
- Generally responds after something starts, rather than blocking it at the kernel boundary.
Some sophisticated techniques will be harder for us to see. We'd rather tell you that than find out you assumed otherwise.
Why we think it's the right trade
It matches the threats you actually face. Small Mac and Linux teams are being hit by infostealers, malicious installers, stolen credentials and poisoned software packages. Those are well within reach of a user-space agent. Kernel rootkits built for a specific target are not what's coming for a 20-person design studio.
It can't take your fleet down. Our worst case is "the agent stopped working on one machine", not "nobody can start their laptop on Monday". For a company without an IT department, that difference is enormous.
Silence is treated as an alert. Without kernel-level tamper protection, the strongest control we have is noticing immediately when an agent stops reporting, so we do. An agent going quiet is raised like any other detection.
If you're evaluating any security vendor, it's worth asking them directly: What runs in the kernel, and what happens if it fails?