The Linux port of the Sysinternals Sysmon tool.
☆286May 7, 2026Updated 3 months ago
Alternatives and similar repositories for SysinternalsEBPF
Users that are interested in SysinternalsEBPF are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sysmon for Linux☆2,144Jul 13, 2026Updated 3 weeks ago
- The common parts of the Sysinternals Sysmon tool shared between the Windows and Linux versions.☆63Apr 23, 2026Updated 3 months ago
- A Linux version of the Procmon Sysinternals tool☆4,715May 7, 2026Updated 3 months ago
- eBPF implementation that runs on top of Windows☆3,538Updated this week
- The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing…☆136Jul 28, 2026Updated last week
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆125Jun 22, 2026Updated last month
- Red Canary's eBPF Sensor☆116Jun 26, 2026Updated last month
- A Linux version of the ProcDump Sysinternals tool☆3,079Jul 29, 2026Updated last week
- ☆15Apr 28, 2023Updated 3 years ago
- ebpfkit is a rootkit powered by eBPF☆853Feb 28, 2023Updated 3 years ago
- A repository of sysmon configuration modules☆3,109Jul 13, 2026Updated 3 weeks ago
- bpflock - eBPF driven security for locking and auditing Linux machines☆157Feb 16, 2022Updated 4 years ago
- A Rust library for managing eBPF programs.☆123Feb 26, 2024Updated 2 years ago
- BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for em…☆481Updated this week
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- An open source library for operating the Windows Overlay Filter driver.☆22Jan 16, 2019Updated 7 years ago
- ☆90Dec 5, 2025Updated 8 months ago
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆121Aug 19, 2025Updated 11 months ago
- Example of building and running an eBPF program in Rust☆33Sep 27, 2018Updated 7 years ago
- Documentation for DFIR ORC, artefact collection tool dedicated to Microsoft Windows☆12May 4, 2026Updated 3 months ago
- Linux Kernel Runtime Integrity with eBPF☆186Nov 23, 2023Updated 2 years ago
- Linux Runtime Security and Forensics using eBPF☆4,572Updated this week
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆306May 24, 2026Updated 2 months ago
- TrustedSec Sysinternals Sysmon Community Guide☆1,430Jun 30, 2026Updated last month
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- An IDA processor for eBPF bytecode☆51Oct 13, 2021Updated 4 years ago
- Dectect syscall hooking using eBPF☆170Apr 28, 2023Updated 3 years ago
- Install a hardware breakpoint in Linux kernel for tracing/debugging☆28Jul 8, 2026Updated last month
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,975Apr 7, 2024Updated 2 years ago
- The Multiplatform Linux Sandbox☆16Dec 19, 2023Updated 2 years ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆221Sep 17, 2019Updated 6 years ago
- Configurations for DFIR ORC☆29Jul 29, 2026Updated last week
- A Linux Host-based Intrusion Detection System based on eBPF.☆455Dec 20, 2023Updated 2 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆335May 2, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆55Jul 8, 2022Updated 4 years ago
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆696Jul 7, 2024Updated 2 years ago
- eBPF kernels and user space tools for BeagleBone SBCs☆10Jan 16, 2022Updated 4 years ago
- Library of threat hunts to get any user started!☆51Sep 4, 2020Updated 5 years ago
- Multiplatform CLI and GUI tool to show information about ELF files☆66Jul 1, 2025Updated last year
- Transform Linux Audit logs for SIEM usage☆849Jul 17, 2026Updated 3 weeks ago
- Orchestration Software for Incident Response☆16Jul 30, 2026Updated last week