smagnani96 / eBPF_TrafficAnalyzer
eBPF C programs injectable in a network card to extract packets' features for detecting different network attacks.
☆12Updated 2 years ago
Alternatives and similar repositories for eBPF_TrafficAnalyzer:
Users that are interested in eBPF_TrafficAnalyzer are comparing it to the libraries listed below
- Snort IDS ported to OpenNetVM☆17Updated 4 years ago
- ☆24Updated 6 years ago
- This project fully automates the process of analyzing and exploiting IoT malware to find live CnC servers.☆41Updated 6 months ago
- A Python based Intrusion Detection and Prevention System. Uses Scapy to sniff packets at a specific interface, extract the remote IPs, sc…☆9Updated 7 years ago
- ssdeep cluster analysis for malware files☆31Updated 4 years ago
- Linux kernel rootkit to hide certain files and processes.☆36Updated 10 years ago
- PoC of injecting code into a running Linux process☆23Updated 5 years ago
- Linux endpoint events for BPF enabled systems☆24Updated 2 years ago
- ☆12Updated 4 years ago
- Dectect syscall hooking using eBPF☆145Updated last year
- A short proof-of-concept how to decrypt ssl traffic WITHOUT the server private TLS certificate☆15Updated 6 years ago
- slides☆9Updated 3 years ago
- Exploits for YARA 3.7.1 & 3.8.1☆30Updated 6 years ago
- ☆15Updated 6 years ago
- ☆8Updated 7 years ago
- Rootkit Detector for UNIX☆62Updated last year
- Using LibVMI to detect malware☆31Updated 2 years ago
- Qiling Advanced Binary Emulation framework☆10Updated 5 years ago
- ☆44Updated 4 years ago
- Static and Dynamic Analysis Added☆9Updated 7 years ago
- Simple LKM linux kernel rootkit (x86 / x86_64)☆23Updated 4 years ago
- Snort/Suricata DAQ module with DPDK patch☆11Updated 10 months ago
- The place where my HackSys Extreme Vulnerable Driver exploits go.☆25Updated 6 years ago
- DbgFlashVul☆12Updated 9 years ago
- ☆28Updated 3 years ago
- Trace deep kernel events through eBPF and lsm hooks☆35Updated 4 years ago
- Linux kernel rootkit using kprobes (From http://phrack.org/issues/67/6.html)☆37Updated 9 years ago
- Windows (ShadowMove) Socket Duplication☆81Updated 4 years ago
- Exploit for uTorrent vulnerability CVE-2020-8437 by whtaguy☆11Updated 4 years ago
- ☆9Updated 7 years ago