pathtofile / bad-bpf
A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29
☆596Updated 9 months ago
Alternatives and similar repositories for bad-bpf:
Users that are interested in bad-bpf are comparing it to the libraries listed below
- ebpfkit is a rootkit powered by eBPF☆789Updated 2 years ago
- BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for em…☆418Updated last week
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆129Updated 2 years ago
- An eBPF playground☆205Updated last year
- A Linux Host-based Intrusion Detection System based on eBPF.☆437Updated last year
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆264Updated this week
- bpflock - eBPF driven security for locking and auditing Linux machines☆147Updated 3 years ago
- Linux Kernel Runtime Integrity with eBPF☆174Updated last year
- A Toolchain to make Build and Run eBPF programs easier☆737Updated 7 months ago
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆290Updated 4 months ago
- Automated upstream mirror for bpftool stand-alone build.☆495Updated 2 weeks ago
- Scaffolding for BPF application development with libbpf and BPF CO-RE☆1,222Updated last week
- The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing…☆106Updated this week
- Userspace eBPF runtime for Observability, Network & General Extensions Framework☆972Updated last week
- Examples of using BPF ring buffer APIs☆124Updated 4 years ago
- Generate eBPF programs and tracing with ChatGPT☆237Updated 8 months ago
- Collection of Linux eBPF slides/documents.☆923Updated last year
- An eBPF program debugger☆204Updated 2 years ago
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆156Updated 7 months ago
- Examples for libbpf, aquasecurity/libbpfgo and cilium/ebpf☆168Updated 2 weeks ago
- Linux kernel rootkit☆342Updated last month
- Dectect syscall hooking using eBPF☆151Updated last year
- Using ftrace for function hooking in Linux kernel☆268Updated 4 years ago
- An effort to comprehensively document eBPF☆351Updated this week
- Linux Kernel Hacking☆684Updated last year
- eBPF library for Go. Powered by libbpf.☆780Updated this week
- CVE-2022-23222: Linux Kernel eBPF Local Privilege Escalation☆566Updated 2 years ago
- Making eBPF programming easier via build env and examples☆478Updated last month
- Utilities and example programs for use with XDP☆712Updated last week
- ☆444Updated 8 months ago