pathtofile / bad-bpfLinks
A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29
☆612Updated 10 months ago
Alternatives and similar repositories for bad-bpf
Users that are interested in bad-bpf are comparing it to the libraries listed below
Sorting:
- ebpfkit is a rootkit powered by eBPF☆798Updated 2 years ago
- BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for em…☆434Updated 3 weeks ago
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆268Updated this week
- A Linux Host-based Intrusion Detection System based on eBPF.☆438Updated last year
- An eBPF playground☆206Updated last year
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆131Updated 2 years ago
- Automated upstream mirror for bpftool stand-alone build.☆516Updated last week
- A Toolchain to make Build and Run eBPF programs easier☆748Updated 8 months ago
- Scaffolding for BPF application development with libbpf and BPF CO-RE☆1,268Updated this week
- Linux Kernel Runtime Integrity with eBPF☆177Updated last year
- Userspace eBPF runtime for Observability, Network, GPU & General Extensions Framework☆1,010Updated this week
- bpflock - eBPF driven security for locking and auditing Linux machines☆147Updated 3 years ago
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,855Updated last year
- The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing…☆115Updated this week
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆158Updated 8 months ago
- Making eBPF programming easier via build env and examples☆490Updated this week
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆293Updated 6 months ago
- Generate eBPF programs and tracing with ChatGPT☆241Updated 9 months ago
- Utilities and example programs for use with XDP☆728Updated this week
- An effort to comprehensively document eBPF☆381Updated this week
- A golang ebpf libary based on cilium/ebpf and datadog/ebpf.☆333Updated 2 weeks ago
- Dectect syscall hooking using eBPF☆153Updated 2 years ago
- Linux Kernel Hacking☆703Updated last year
- Using ftrace for function hooking in Linux kernel☆272Updated 4 years ago
- An eBPF program debugger☆209Updated 3 years ago
- Examples of using BPF ring buffer APIs☆127Updated 4 years ago
- ☆451Updated 9 months ago
- Red-Team Linux kernel rootkit☆478Updated last month
- CVE-2022-23222: Linux Kernel eBPF Local Privilege Escalation☆567Updated 2 years ago
- ☆302Updated last year