Vali-Cyber / ebpf-attacks
A collection of bypasses and exploits for eBPF-based cloud security.
β15Updated 9 months ago
Related projects β
Alternatives and complementary repositories for ebpf-attacks
- β83Updated 4 months ago
- π Ransomware Detection using Machine Learning with eBPF for Linux.β53Updated 4 months ago
- Red Canary's eBPF Sensorβ101Updated 4 months ago
- A tool to render a pie chart of memory usage (bytes_memlock) of BPF maps on the system π₯§β18Updated 4 months ago
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPFβ149Updated 2 months ago
- bpflock - eBPF driven security for locking and auditing Linux machinesβ136Updated 2 years ago
- OCI hook to trace syscalls and generate a seccomp profileβ303Updated this week
- proof-of-concept example of using eBPF to Monitor for eBPF Map tamperingβ20Updated 3 years ago
- π BPFBox π¦ Exploring process confinement in eBPFβ101Updated 9 months ago
- Generative and mutative fuzzer for Kubernetes admission controller chains by automatically parsing the cluster api specification.β70Updated last year
- Process-based Confidential Container Runtimeβ79Updated this week
- Example BPF program with LSM hooksβ31Updated 3 years ago
- Operator to deploy confidential containers runtimeβ112Updated this week
- This repo contains various examples to learn, explore, and experiment with eBPF.β31Updated this week
- An eBPF playgroundβ195Updated 10 months ago
- A process level network security monitoring and enforcement project for Kubernetes, using eBPFβ40Updated 4 years ago
- Linux Kernel Runtime Integrity with eBPFβ163Updated 11 months ago
- This tool set can generate SECCOMP profiles for Docker images. It mainly relies on static analysis, making its results more reliable thanβ¦β62Updated 2 years ago
- Kernel-based Process Monitoring on Linux Endpoints for File System, TCP and UDP Networking Events and optionally DNS, HTTP and SYSLOG Appβ¦β44Updated this week
- monitor and protect SSH sessions with eBPFβ65Updated 3 years ago
- Attestation and Secret Delivery Componentsβ66Updated this week
- β34Updated last year
- Ebpf faqs, samples, toolingβ44Updated 3 years ago
- LSM BPF module to block pwnkit (CVE-2021-4034) like exploitsβ20Updated 2 years ago
- agent for handling seccomp descriptors for container runtimesβ41Updated 9 months ago
- Sample ebpf programs to analyzeβ91Updated last month
- eBPF-based network diagnosis tool for Linuxβ25Updated 5 months ago
- Tracing packets in the Linux networking stack & friendsβ94Updated this week
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkitsβ123Updated last year
- Open Source eBPF defined Cloud Native Advanced 5G Coreβ9Updated this week