The Linux port of the Sysinternals Sysmon tool.
☆282Apr 8, 2026Updated 2 weeks ago
Alternatives and similar repositories for SysinternalsEBPF
Users that are interested in SysinternalsEBPF are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sysmon for Linux☆2,096Updated this week
- The common parts of the Sysinternals Sysmon tool shared between the Windows and Linux versions.☆64Updated this week
- A Linux version of the Procmon Sysinternals tool☆4,672Apr 10, 2026Updated 2 weeks ago
- An open source library for operating the Windows Overlay Filter driver.☆22Jan 16, 2019Updated 7 years ago
- A Linux version of the ProcDump Sysinternals tool☆3,069Apr 8, 2026Updated 2 weeks ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆15Apr 28, 2023Updated 3 years ago
- ebpfkit is a rootkit powered by eBPF☆846Feb 28, 2023Updated 3 years ago
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆123Mar 30, 2026Updated 3 weeks ago
- Configurations for DFIR ORC☆28Mar 28, 2024Updated 2 years ago
- ☆25Jan 12, 2026Updated 3 months ago
- Dectect syscall hooking using eBPF☆170Apr 28, 2023Updated 3 years ago
- A repository of sysmon configuration modules☆3,029Aug 21, 2024Updated last year
- iptables-trace is an eBPF enhanced iptables-TRACE alternative iptables TRACE. GPL-3.0 license☆14Feb 3, 2025Updated last year
- Golang Tool to interact with Launchd and other services with XPC☆29May 7, 2020Updated 5 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆305Nov 30, 2024Updated last year
- A Powershell script for frequency analysis of separated values data files.☆17Jan 22, 2014Updated 12 years ago
- ☆16Apr 16, 2017Updated 9 years ago
- eBPF implementation that runs on top of Windows☆3,479Updated this week
- A K8s ClusterIP HTTP monitoring library based on eBPF☆18May 23, 2021Updated 4 years ago
- ☆13Apr 30, 2020Updated 5 years ago
- This repository contains a set of rules samples that can be directly used with Trellix Endpoint Security, in the Exploit Prevention polic…☆31Mar 26, 2026Updated last month
- This is the Linux kernel module event collector for the Carbon Black Cloud.☆19Aug 4, 2023Updated 2 years ago
- Linux Kernel module for Carbon Black EDR☆12Dec 11, 2020Updated 5 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,959Apr 7, 2024Updated 2 years ago
- Set of scripts to index PCAP files and retrieve packets☆14Sep 10, 2015Updated 10 years ago
- An eBPF kernel Observable Agent To Spy Performance Issue On OS.☆13Oct 31, 2025Updated 5 months ago
- bpflock - eBPF driven security for locking and auditing Linux machines☆152Feb 16, 2022Updated 4 years ago
- Exploring RPC interfaces on Windows☆351Jan 30, 2024Updated 2 years ago
- ☆92Dec 5, 2025Updated 4 months ago
- Indicators of compromise☆17Jan 29, 2026Updated 3 months ago
- sopacker是一个用于打包可执行文件和动态库的脚本工程. 生成的新可执行文件可以在大部分Linux上运行. sopacker is a script for packaging an executable file and all its dependent dynam…☆16Nov 14, 2025Updated 5 months ago
- ☆14Dec 26, 2022Updated 3 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- TrustedSec Sysinternals Sysmon Community Guide☆1,397Feb 10, 2026Updated 2 months ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆124Nov 19, 2020Updated 5 years ago
- Elastic Security detection content for Endpoint☆1,418Apr 13, 2026Updated 2 weeks ago
- Linux Kernel Runtime Integrity with eBPF☆186Nov 23, 2023Updated 2 years ago
- The Multiplatform Linux Sandbox☆16Dec 19, 2023Updated 2 years ago
- ☆82Sep 29, 2025Updated 7 months ago
- PoC of injecting code into a running Linux process☆23Sep 11, 2019Updated 6 years ago