CrowdStrike / bpfmon-example
proof-of-concept example of using eBPF to Monitor for eBPF Map tampering
☆21Updated 3 years ago
Alternatives and similar repositories for bpfmon-example:
Users that are interested in bpfmon-example are comparing it to the libraries listed below
- eBPF Library for Go☆29Updated 10 months ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- monitor and protect SSH sessions with eBPF☆66Updated 3 years ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆127Updated 2 years ago
- ☆86Updated 8 months ago
- ☆25Updated 10 months ago
- Kubernetes offensive framework built in eBPF☆37Updated 2 years ago
- agent for handling seccomp descriptors for container runtimes☆45Updated last year
- Code coverage tooling for eBPF☆36Updated 8 months ago
- Publications from the eBPF foundation☆22Updated 4 months ago
- Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster☆36Updated 3 years ago
- bpflock - eBPF driven security for locking and auditing Linux machines☆146Updated 3 years ago
- Trace deep kernel events through eBPF and lsm hooks☆35Updated 4 years ago
- Inspect SSL/TLS traffic using eBPF☆19Updated 5 months ago
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆118Updated last year
- eBPF programs without a libbcc dependency☆59Updated last year
- A file system events notifier based on eBPF☆61Updated 2 years ago
- 🐝 BPFBox 📦 Exploring process confinement in eBPF☆101Updated last year
- Use eBPF to inject chaos into local processes☆64Updated 6 months ago
- ebpf compiler in Go; Write Go, get ebpf☆33Updated 4 months ago
- ☆23Updated 4 years ago
- Ebpf faqs, samples, tooling☆44Updated 3 years ago
- CO-RE code for the Netdata eBPF plugin.☆13Updated 4 months ago
- A collection of bypasses and exploits for eBPF-based cloud security.☆21Updated last year
- Example BPF program with LSM hooks☆33Updated 4 years ago
- An eBPF detection program for CVE-2022-0847☆28Updated 2 years ago
- ☆25Updated 6 years ago
- Kernel-based Process Monitoring on Linux Endpoints for File System, TCP and UDP Networking Events and optionally DNS, HTTP and SYSLOG App…☆58Updated this week
- A repository to store Rad Fingerprinting data.☆24Updated 7 months ago
- Kubernetes operator for bpfman☆21Updated this week