pathtofile / bad-bpfLinks
A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29
☆650Updated last year
Alternatives and similar repositories for bad-bpf
Users that are interested in bad-bpf are comparing it to the libraries listed below
Sorting:
- ebpfkit is a rootkit powered by eBPF☆809Updated 2 years ago
- BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for em…☆454Updated this week
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆287Updated this week
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆136Updated 2 years ago
- An eBPF playground☆207Updated last year
- Scaffolding for BPF application development with libbpf and BPF CO-RE☆1,337Updated 3 months ago
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,900Updated last year
- Linux Kernel Runtime Integrity with eBPF☆182Updated last year
- A Linux Host-based Intrusion Detection System based on eBPF.☆442Updated last year
- A Toolchain to make Build and Run eBPF programs easier☆786Updated last month
- The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing…☆122Updated last week
- Collection of Linux eBPF slides/documents.☆955Updated last year
- bpflock - eBPF driven security for locking and auditing Linux machines☆150Updated 3 years ago
- Automated upstream mirror for bpftool stand-alone build.☆574Updated last week
- Examples for aquasecurity/libbpfgo and cilium/ebpf☆180Updated 3 months ago
- Userspace eBPF runtime for Observability, Network, GPU & General Extensions Framework☆1,090Updated this week
- Generate eBPF programs and tracing with ChatGPT☆252Updated last month
- Get live information about applications that make network requests (based on eBPF)☆51Updated 7 months ago
- Process-aware, eBPF-based tcpdump☆1,092Updated last week
- Dectect syscall hooking using eBPF☆161Updated 2 years ago
- ☆463Updated 2 months ago
- Linux Kernel Hacking☆736Updated last year
- An eBPF program debugger☆212Updated 3 years ago
- Automated upstream mirror for libbpf stand-alone build.☆2,485Updated 2 weeks ago
- Red-Team Linux kernel rootkit☆550Updated 2 weeks ago
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆166Updated last year
- ☆25Updated last year
- ☆309Updated 2 years ago
- Making eBPF programming easier via build env and examples☆508Updated last week
- A file system events notifier based on eBPF☆72Updated 2 years ago