CrowdStrike / bpfmon-example
proof-of-concept example of using eBPF to Monitor for eBPF Map tampering
☆21Updated 3 years ago
Alternatives and similar repositories for bpfmon-example:
Users that are interested in bpfmon-example are comparing it to the libraries listed below
- eBPF Library for Go☆29Updated 8 months ago
- monitor and protect SSH sessions with eBPF☆66Updated 3 years ago
- ☆85Updated 6 months ago
- A file system events notifier based on eBPF☆60Updated last year
- LSM BPF module to block pwnkit (CVE-2021-4034) like exploits☆21Updated 2 years ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- bpflock - eBPF driven security for locking and auditing Linux machines☆140Updated 2 years ago
- Publications from the eBPF foundation☆22Updated 2 months ago
- Code coverage tooling for eBPF☆36Updated 5 months ago
- Source-code based coverage for eBPF programs actually running in the Linux kernel☆129Updated 2 years ago
- 🐝 BPFBox 📦 Exploring process confinement in eBPF☆101Updated last year
- eBPF based syscalls, files and network events tracing framework☆90Updated 4 years ago
- Use eBPF to inject chaos into local processes☆64Updated 4 months ago
- Shape your traffic the BPF way☆79Updated last year
- ebpf compiler in Go; Write Go, get ebpf☆31Updated 2 months ago
- eBPF Programs☆59Updated last month
- Linux Kernel Runtime Integrity with eBPF☆172Updated last year
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆125Updated last year
- Trace deep kernel events through eBPF and lsm hooks☆35Updated 3 years ago
- agent for handling seccomp descriptors for container runtimes☆43Updated 11 months ago
- Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster☆36Updated 2 years ago
- Example BPF program with LSM hooks☆32Updated 3 years ago
- Inspect SSL/TLS traffic using eBPF☆16Updated 3 months ago
- calltop is a tracing tool. It provides a dynamic real-time view of system calls on Linux. It traces also python, java, php and ruby funct…☆28Updated 3 years ago
- CO-RE code for the Netdata eBPF plugin.☆12Updated 2 months ago
- A process level network security monitoring and enforcement project for Kubernetes, using eBPF☆41Updated 4 years ago
- Ebpf faqs, samples, tooling☆44Updated 3 years ago
- A crawler for kernel releases distributed by the major Linux distributions.☆13Updated 3 months ago