A lightweight, extensible forensic tool that leverages eBPF to collect real-time system events on Windows for Digital Forensics and Incident Response.
☆20Aug 26, 2025Updated 11 months ago
Alternatives and similar repositories for eBPF-for-DFIR
Users that are interested in eBPF-for-DFIR are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- *For research purposes only*. Some proof of concept code to trig vulnerability or exploit them that I found before.☆25Oct 24, 2025Updated 9 months ago
- vxlan protocol / unknown unicast flooding technique + eBPF☆25Jul 4, 2026Updated last month
- eBPF-based tool can trace GPU memory leaks by processes in Linux.☆15Sep 26, 2025Updated 10 months ago
- Logpresso Mini and community contents for incident response☆21Oct 21, 2021Updated 4 years ago
- Implementing TCP/IP in Rust leveraging eBPF/XDP☆21Mar 30, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Process Hollowing in Rust with Process Executable Relocation Support for both 32 and 64 bit architecture environments.☆26Jan 6, 2025Updated last year
- Listen to database queries going through your system with eBPF☆19Aug 3, 2025Updated last year
- High-Performance XDP Firewall & Traffic Analyzer written in Rust.☆20Updated this week
- ☆12Nov 17, 2020Updated 5 years ago
- A developer tool for disassembling, analyzing, debugging, and visualizing BPF object files.☆26Feb 11, 2026Updated 6 months ago
- BPFView: Process and Network Activity Correlation☆34May 17, 2025Updated last year
- eBPF Security Monitoring and Sandboxing Agent Based on Aya☆53Aug 3, 2026Updated last week
- A Python-base EBPF code generator☆38Jun 22, 2026Updated last month
- A high-performance, distributed Zero Trust firewall using eBPF/XDP. Aegis enforces identity-based micro-segmentation, dynamically opening…☆49Apr 19, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Demo repository for all the different ways to do eBPF Tracing☆19Feb 9, 2026Updated 6 months ago
- 🖍 Color System of Universities☆21Oct 29, 2019Updated 6 years ago
- Translate and Transcribe videos using AWS☆12Oct 21, 2024Updated last year
- ☆16Jan 30, 2025Updated last year
- Curated list of lovely K-Pop girl group TWICE☆25Jan 1, 2016Updated 10 years ago
- MCP server: using eBPF to tracing your kernel☆72Feb 12, 2026Updated 5 months ago
- Go module for running eBPF programs without root privileges or kernel eBPF support, powered by bpftime.☆15Feb 9, 2026Updated 6 months ago
- eBPF-based Ethernet traffic monitor using TC, XDP, kprobes and cgroups☆149Jul 22, 2026Updated 2 weeks ago
- Building Truly Portable eBPF Programs☆22Apr 26, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A collection of Docker and Kubernetes resources☆18Nov 14, 2022Updated 3 years ago
- Helping people get healthier through organic nutrition☆12Jul 10, 2024Updated 2 years ago
- Build the Linux kernel into OCI images, suitable for Edera products.☆23Updated this week
- XDP Based Lightweight and Fast Firewall☆70Feb 23, 2026Updated 5 months ago
- Simple tool to extract icons from a pe file and other useful information☆13Jun 22, 2018Updated 8 years ago
- A port of Brendan Gregg's eBPF profile.py application to Golang.☆29Mar 25, 2025Updated last year
- Demo repository for running eBPF in GitHub Actions☆23Mar 27, 2025Updated last year
- Inspect SSL/TLS traffic using eBPF☆21Oct 19, 2024Updated last year
- Wasp: micro-hypervisor that enables lightweight, isolated virtines☆20Mar 31, 2023Updated 3 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Script for automating Linux memory capture and analysis☆12May 6, 2020Updated 6 years ago
- ☆23Jul 1, 2026Updated last month
- Orchestration and memory for multi-agent systems☆16Jul 26, 2026Updated 2 weeks ago
- This eBPF module will drop any IPv4 packets that have the RFC 3514 "evil bit" set.☆19Jun 16, 2025Updated last year
- eBPF practice and learning repo☆18Dec 7, 2025Updated 8 months ago
- Example architectures utilizing DevSecOps principles to deploy F5 Application Delivery and Security Platform solutions.☆23Sep 25, 2025Updated 10 months ago
- Linux /proc data in a consistent, parsed format.☆10Mar 28, 2016Updated 10 years ago