tarsal-oss / kflowd
Kernel-based Process Monitoring on Linux Endpoints for File System, TCP and UDP Networking Events and optionally DNS, HTTP and SYSLOG Application Messages via eBPF Subsystem
☆55Updated this week
Alternatives and similar repositories for kflowd:
Users that are interested in kflowd are comparing it to the libraries listed below
- ☆85Updated 6 months ago
- Kubernetes offensive framework built in eBPF☆36Updated last year
- Use eBPF to inject chaos into local processes☆64Updated 4 months ago
- Publications from the eBPF foundation☆22Updated 2 months ago
- 🐝 Ransomware Detection using Machine Learning with eBPF for Linux.☆58Updated last month
- ☆62Updated last year
- Intent driven security automation framework☆25Updated this week
- An EBPF based IPv4/IPv6 firewall with integrations for OpenZiti Zero-Trust Framework edge-routers and tunnellers☆46Updated last month
- Ingress node firewall implements Kubernetes operator to provision stateless ingress node level firewall rules, stateless ingress node fir…☆51Updated this week
- Generative and mutative fuzzer for Kubernetes admission controller chains by automatically parsing the cluster api specification.☆71Updated last year
- Red Canary's eBPF Sensor☆101Updated 6 months ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- monitor and protect SSH sessions with eBPF☆66Updated 3 years ago
- ☆36Updated this week
- proof-of-concept example of using eBPF to Monitor for eBPF Map tampering☆21Updated 3 years ago
- Sniff and attack networks that use IP-in-IP or VXLAN encapsulation protocols.☆21Updated 4 months ago
- A simple mitmproxy blueprint to intercept HTTPS traffic from app running on Kubernetes☆64Updated 6 months ago
- Elastic's eBPF☆67Updated this week
- Gain insight into any Linux command or application with no code modification☆38Updated last month
- A toy containers aware firewall built in Rust☆22Updated 2 years ago
- eBPF Programs☆59Updated last month
- A replacement for "kubectl exec" that works over WebSocket connections.☆36Updated 9 months ago
- Red team tool that emulates the SolarWinds CI compromise attack vector.☆22Updated 10 months ago
- K8s API Honeypot with Active Defense Capabilities☆40Updated last year
- A collection of bypasses and exploits for eBPF-based cloud security.☆19Updated last year
- egrets monitors egress☆46Updated 4 years ago
- Adversary emulation for EDR/SIEM testing (macOS/Linux)☆39Updated 11 months ago
- ☆20Updated 8 months ago
- Kubernetes audit logging, when you don't control the control plane☆67Updated this week
- A file system events notifier based on eBPF☆60Updated last year