pathtofile / bad-bpfLinks
A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29
☆679Updated last year
Alternatives and similar repositories for bad-bpf
Users that are interested in bad-bpf are comparing it to the libraries listed below
Sorting:
- ebpfkit is a rootkit powered by eBPF☆831Updated 2 years ago
- BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for em…☆470Updated 2 weeks ago
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆301Updated this week
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆139Updated 2 years ago
- The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing…☆131Updated this week
- A Linux Host-based Intrusion Detection System based on eBPF.☆457Updated 2 years ago
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,936Updated last year
- bpflock - eBPF driven security for locking and auditing Linux machines☆151Updated 3 years ago
- An eBPF playground☆210Updated 2 years ago
- Linux Kernel Runtime Integrity with eBPF☆184Updated 2 years ago
- Scaffolding for BPF application development with libbpf and BPF CO-RE☆1,429Updated last month
- Examples for aquasecurity/libbpfgo and cilium/ebpf☆188Updated last week
- Collection of Linux eBPF slides/documents.☆978Updated 2 years ago
- Automated upstream mirror for bpftool stand-alone build.☆634Updated last week
- A Tool to make Build and Run eBPF programs easier☆845Updated 4 months ago
- Get live information about applications that make network requests (based on eBPF)☆54Updated 4 months ago
- Dectect syscall hooking using eBPF☆168Updated 2 years ago
- Examples of using BPF ring buffer APIs☆137Updated 5 years ago
- ☆470Updated 3 months ago
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆305Updated last year
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆168Updated last year
- Linux Kernel Hacking☆747Updated last year
- Process-aware, eBPF-based tcpdump☆1,196Updated 3 weeks ago
- A file system events notifier based on eBPF☆73Updated 2 months ago
- Generate eBPF programs and tracing with ChatGPT☆269Updated 6 months ago
- eBPF library for Go. Powered by libbpf.☆836Updated 2 weeks ago
- Using ftrace for function hooking in Linux kernel☆294Updated 4 years ago
- ☆25Updated 2 years ago
- An effort to comprehensively document eBPF☆488Updated this week
- Trace deep kernel events through eBPF and lsm hooks☆42Updated 5 years ago