thought-machine / falco-probes
Automated build and mirror of eBPF kernel probes for use as a driver with the Falco runtime security agent (https://falco.org/)
☆16Updated 5 months ago
Alternatives and similar repositories for falco-probes:
Users that are interested in falco-probes are comparing it to the libraries listed below
- Kubernetes audit logging, when you don't control the control plane☆74Updated this week
- agent for handling seccomp descriptors for container runtimes☆46Updated last year
- Generate a variety of suspect actions that are detected by Falco rulesets☆103Updated last month
- Manage AppAmormor profiles for Kubernetes cluster☆41Updated last year
- A tool for in-depth analysis of container checkpoints☆113Updated 3 weeks ago
- Falco Running with Ptrace(2) for Kernel Events☆36Updated 4 years ago
- A process level network security monitoring and enforcement project for Kubernetes, using eBPF☆43Updated 4 years ago
- K8s API Honeypot with Active Defense Capabilities☆40Updated last year
- sigstore the hard way!☆111Updated 11 months ago
- A replacement for "kubectl exec" that works over WebSocket connections.☆38Updated last year
- 🐝 BPFBox 📦 Exploring process confinement in eBPF☆102Updated last year
- Administrative tooling for Falco☆102Updated this week
- ptrace-based event producer for udig☆67Updated 2 years ago
- Code coverage tooling for eBPF☆37Updated 9 months ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated last week
- eBPF tool for logging process ancestry of outbound TCP connections