Yelp / pidtree-bcc
eBPF tool for logging process ancestry of outbound TCP connections
☆42Updated 2 weeks ago
Alternatives and similar repositories for pidtree-bcc:
Users that are interested in pidtree-bcc are comparing it to the libraries listed below
- ptrace-based event producer for udig☆67Updated 2 years ago
- IOModule manager and plugins☆38Updated 7 years ago
- Simplifying Seccomp enforcement in containerized or non-containerized apps☆110Updated 4 years ago
- Falco Running with Ptrace(2) for Kernel Events☆36Updated 4 years ago
- 🐝 BPFBox 📦 Exploring process confinement in eBPF☆101Updated last year
- The Container Security Book—a free book for practitioners☆82Updated 4 years ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- Build custom Docker seccomp profiles for containers by finding syscalls it uses.☆89Updated 4 years ago
- agent for handling seccomp descriptors for container runtimes☆44Updated 11 months ago
- BPF based FIM solution☆42Updated last year
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆115Updated last year
- ☆42Updated 4 years ago
- Automated build and mirror of eBPF kernel probes for use as a driver with the Falco runtime security agent (https://falco.org/)☆16Updated 2 months ago
- A command line tool to automatically generate seccomp profiles.☆25Updated 3 years ago
- egrets monitors egress☆46Updated 4 years ago
- ☆19Updated 5 years ago
- Slides and Workshop Instructions for a BPF Introduction @Sqreen☆11Updated 5 years ago
- Easier tracing of packets through iptables☆32Updated 8 months ago
- A tool to list and diagnose bpf programs. (Who watches the watchers..? :)☆95Updated 4 years ago
- Documentation for Prodfiler, the distributed lightweight continuous whole-system profiler☆61Updated last year
- Now moved into `github.com/inspektor-gadget/inspektor-gadget/pkg/gadget-collection/gadgets/traceloop`. Tracing system calls in cgroups u…☆198Updated last year
- Let's share some eBPF love!☆45Updated 4 years ago
- Provides agent and server plugins for SPIRE to allow TPM 2-based node attestation.☆76Updated last year
- cloud native software supply chain ☁️🔗☆63Updated 3 years ago
- ## Auto-archived due to inactivity. ## profile eBPF programs from Go☆87Updated last year
- Kilt is a project that defines how to inject foreign apps into containers☆13Updated last year
- ☆37Updated 4 years ago
- Utility based on bpftool to manage eBPF maps☆12Updated 5 years ago
- How to connect eBPF with prometheus to create nice dashboards with Kernel stuff in them☆31Updated 5 years ago
- Source-code based coverage for eBPF programs actually running in the Linux kernel☆129Updated 2 years ago