capelabs / eBPF-for-DFIRView on GitHub
A lightweight, extensible forensic tool that leverages eBPF to collect real-time system events on Windows for Digital Forensics and Incident Response.
20Aug 26, 2025Updated 10 months ago

Alternatives and similar repositories for eBPF-for-DFIR

Users that are interested in eBPF-for-DFIR are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.

Sorting:

Are these results useful?