The Linux port of the Sysinternals Sysmon tool.
☆288May 7, 2026Updated 3 months ago
Alternatives and similar repositories for SysinternalsEBPF
Users that are interested in SysinternalsEBPF are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sysmon for Linux☆2,153Jul 13, 2026Updated last month
- The common parts of the Sysinternals Sysmon tool shared between the Windows and Linux versions.☆63Apr 23, 2026Updated 4 months ago
- A Linux version of the Procmon Sysinternals tool☆4,732May 7, 2026Updated 3 months ago
- eBPF implementation that runs on top of Windows☆3,555Updated this week
- The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing…☆136Jul 28, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆126Jun 22, 2026Updated 2 months ago
- Red Canary's eBPF Sensor☆116Jun 26, 2026Updated 2 months ago
- A Linux version of the ProcDump Sysinternals tool☆3,083Updated this week
- ☆15Apr 28, 2023Updated 3 years ago
- ebpfkit is a rootkit powered by eBPF☆855Feb 28, 2023Updated 3 years ago
- A repository of sysmon configuration modules☆3,119Aug 10, 2026Updated 2 weeks ago
- bpflock - eBPF driven security for locking and auditing Linux machines☆157Feb 16, 2022Updated 4 years ago
- A Rust library for managing eBPF programs.☆123Feb 26, 2024Updated 2 years ago
- BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for em…☆484Aug 3, 2026Updated 3 weeks ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- An open source library for operating the Windows Overlay Filter driver.☆22Jan 16, 2019Updated 7 years ago
- ☆90Dec 5, 2025Updated 8 months ago
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆122Aug 19, 2025Updated last year
- Example of building and running an eBPF program in Rust☆33Sep 27, 2018Updated 7 years ago
- Documentation for DFIR ORC, artefact collection tool dedicated to Microsoft Windows☆12May 4, 2026Updated 3 months ago
- Linux Kernel Runtime Integrity with eBPF☆186Nov 23, 2023Updated 2 years ago
- Linux Runtime Security and Forensics using eBPF☆4,595Aug 11, 2026Updated 2 weeks ago
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆306May 24, 2026Updated 3 months ago
- TrustedSec Sysinternals Sysmon Community Guide☆1,431Jun 30, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- An IDA processor for eBPF bytecode☆51Oct 13, 2021Updated 4 years ago
- Dectect syscall hooking using eBPF☆170Apr 28, 2023Updated 3 years ago
- Install a hardware breakpoint in Linux kernel for tracing/debugging☆29Jul 8, 2026Updated last month
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,977Apr 7, 2024Updated 2 years ago
- The Multiplatform Linux Sandbox☆16Dec 19, 2023Updated 2 years ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆222Sep 17, 2019Updated 6 years ago
- Configurations for DFIR ORC☆29Jul 29, 2026Updated last month
- A Linux Host-based Intrusion Detection System based on eBPF.☆457Dec 20, 2023Updated 2 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆336Aug 15, 2026Updated 2 weeks ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆55Jul 8, 2022Updated 4 years ago
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆697Jul 7, 2024Updated 2 years ago
- eBPF kernels and user space tools for BeagleBone SBCs☆10Jan 16, 2022Updated 4 years ago
- Library of threat hunts to get any user started!☆51Sep 4, 2020Updated 5 years ago
- Transform Linux Audit logs for SIEM usage☆856Updated this week
- Examples of using BPF ring buffer APIs☆142Oct 26, 2020Updated 5 years ago
- Exploring RPC interfaces on Windows☆364Jan 30, 2024Updated 2 years ago