CrowdStrike / bpfmon-example
proof-of-concept example of using eBPF to Monitor for eBPF Map tampering
☆21Updated 4 years ago
Alternatives and similar repositories for bpfmon-example:
Users that are interested in bpfmon-example are comparing it to the libraries listed below
- Source-code based coverage for eBPF programs actually running in the Linux kernel☆132Updated 3 months ago
- LSM BPF module to block pwnkit (CVE-2021-4034) like exploits☆21Updated 3 years ago
- ☆88Updated 10 months ago
- Kernel-based Process Monitoring on Linux Endpoints for File System, TCP and UDP Networking Events and optionally DNS, HTTP and SYSLOG App…☆62Updated last month
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated last week
- monitor and protect SSH sessions with eBPF☆68Updated 3 years ago
- Easier tracing of packets through iptables☆33Updated 2 months ago
- A file system events notifier based on eBPF☆66Updated 2 years ago
- agent for handling seccomp descriptors for container runtimes☆46Updated last year
- Example BPF program with LSM hooks☆33Updated 4 years ago
- Publications from the eBPF foundation☆23Updated 5 months ago
- Trace deep kernel events through eBPF and lsm hooks☆35Updated 4 years ago
- 🐝 BPFBox 📦 Exploring process confinement in eBPF☆102Updated last year
- ebpf compiler in Go; Write Go, get ebpf☆33Updated 6 months ago
- ☆23Updated 4 years ago
- Code coverage tooling for eBPF☆37Updated 9 months ago
- ☆70Updated this week
- Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster☆36Updated 3 years ago
- Detect compiler names and versions from ELF files☆26Updated 7 months ago
- bpflock - eBPF driven security for locking and auditing Linux machines☆147Updated 3 years ago
- A collection of bypasses and exploits for eBPF-based cloud security.☆22Updated last year
- Ebpf faqs, samples, tooling☆45Updated 3 years ago
- An eBPF detection program for CVE-2022-0847☆28Updated 2 years ago
- eBPF Library for Go☆29Updated last week
- eBPF Programs☆60Updated last month
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆116Updated 2 years ago
- A crawler for kernel releases distributed by the major Linux distributions.☆13Updated 6 months ago
- Simple project to demonstrate the loading of eBPF programs via florianl/go-tc.☆34Updated 3 weeks ago
- Use eBPF to inject chaos into local processes☆64Updated 7 months ago
- An query language and interactive tooling to work with SBOM data.☆14Updated 7 months ago