Gui774ume / ebpfkit
ebpfkit is a rootkit powered by eBPF
☆761Updated last year
Related projects ⓘ
Alternatives and complementary repositories for ebpfkit
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆549Updated 4 months ago
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,786Updated 7 months ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆123Updated last year
- Linux Kernel Hacking☆640Updated 7 months ago
- Linux Kernel Runtime Integrity with eBPF☆164Updated 11 months ago
- An eBPF playground☆195Updated 11 months ago
- A Linux Host-based Intrusion Detection System based on eBPF.☆409Updated 11 months ago
- BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for em…☆389Updated 4 months ago
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆282Updated 3 weeks ago
- ☆296Updated last year
- bpflock - eBPF driven security for locking and auditing Linux machines☆136Updated 2 years ago
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆150Updated 2 months ago
- Scaffolding for BPF application development with libbpf and BPF CO-RE☆1,102Updated this week
- Linux kernel rootkit☆278Updated this week
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆232Updated this week
- Credentials Dumper for Linux using eBPF☆1,116Updated 2 months ago
- CVE-2022-23222: Linux Kernel eBPF Local Privilege Escalation☆559Updated 2 years ago
- Dectect syscall hooking using eBPF☆139Updated last year
- The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing…☆95Updated this week
- Process-aware, eBPF-based tcpdump☆567Updated this week
- ☆427Updated 3 months ago
- Userspace eBPF runtime for Observability, Network & General Extensions Framework☆829Updated 3 weeks ago
- Linux EDR written in Golang and based on eBPF.☆229Updated 2 years ago
- eBPF library for Go. Powered by libbpf.☆735Updated last week
- Automated upstream mirror for bpftool stand-alone build.☆413Updated last week
- Generate eBPF programs and tracing with ChatGPT☆225Updated 3 months ago
- Collection of Linux eBPF slides/documents.☆872Updated last year
- An eBPF program debugger☆197Updated 2 years ago
- Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.☆1,569Updated last year
- Red Canary's eBPF Sensor☆101Updated 4 months ago