Gui774ume / ebpfkit
ebpfkit is a rootkit powered by eBPF
☆782Updated 2 years ago
Alternatives and similar repositories for ebpfkit:
Users that are interested in ebpfkit are comparing it to the libraries listed below
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆592Updated 8 months ago
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,826Updated 11 months ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆127Updated 2 years ago
- A Linux Host-based Intrusion Detection System based on eBPF.☆437Updated last year
- Linux Kernel Runtime Integrity with eBPF☆173Updated last year
- BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for em…☆411Updated 3 weeks ago
- Linux Kernel Hacking☆672Updated 11 months ago
- An eBPF playground☆204Updated last year
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆290Updated 3 months ago
- ☆300Updated last year
- bpflock - eBPF driven security for locking and auditing Linux machines☆146Updated 3 years ago
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆262Updated this week
- Dectect syscall hooking using eBPF☆149Updated last year
- CVE-2022-23222: Linux Kernel eBPF Local Privilege Escalation☆565Updated 2 years ago
- Linux kernel rootkit☆336Updated last month
- The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing…☆105Updated last week
- eBPF library for Go. Powered by libbpf.☆773Updated last week
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆155Updated 6 months ago
- Credentials Dumper for Linux using eBPF☆1,136Updated 6 months ago
- ☆439Updated 7 months ago
- Scaffolding for BPF application development with libbpf and BPF CO-RE☆1,202Updated last week
- Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.☆1,595Updated last year
- Making eBPF programming easier via build env and examples☆467Updated 3 weeks ago
- A Toolchain to make Build and Run eBPF programs easier☆728Updated 6 months ago
- Using ftrace for function hooking in Linux kernel☆266Updated 4 years ago
- An effort to comprehensively document eBPF☆342Updated this week
- An eBPF program debugger☆203Updated 2 years ago
- Generate eBPF programs and tracing with ChatGPT☆235Updated 7 months ago
- Collection of Linux eBPF slides/documents.☆917Updated last year
- Automated upstream mirror for bpftool stand-alone build.☆480Updated last month