yasukata / zpoline
system call hook for Linux
☆565Updated 3 months ago
Alternatives and similar repositories for zpoline:
Users that are interested in zpoline are comparing it to the libraries listed below
- Userspace eBPF runtime for Observability, Network & General Extensions Framework☆972Updated last week
- eBPF verifier based on abstract interpretation☆411Updated this week
- Investigate kernel error call stacks☆253Updated 5 months ago
- 📡🐧 Linux kernel syscall implementation tracker☆210Updated 3 weeks ago
- blazesym is a library for address symbolization and related tasks☆164Updated this week
- An eBPF program debugger☆204Updated 2 years ago
- Userspace eBPF VM☆885Updated this week
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆596Updated 9 months ago
- Using ftrace for function hooking in Linux kernel☆268Updated 4 years ago
- Userspace eBPF VM with llvm JIT/AOT compiler☆64Updated last week
- Linux Kernel hooking engine (x86)☆342Updated 4 months ago
- A powerful static binary rewriting tool☆1,017Updated this week
- ebpfkit is a rootkit powered by eBPF☆789Updated 2 years ago
- An eBPF playground☆205Updated last year
- 🌐🐧 Browsable Linux kernel syscall tables built with Systrack (https://github.com/mebeim/systrack)☆169Updated last week
- Modernized kernel functions, kernel tracepoints and bpf progs tracing tool for the bpf era.☆77Updated this week
- KVM-based Virtual Machine Introspection☆335Updated 5 months ago
- Examples of using BPF ring buffer APIs☆124Updated 4 years ago
- High-performance QEMU memory and instruction tracing☆543Updated 8 months ago
- Reference setup for Linux kernel development in VSCode☆241Updated last month
- Sample ebpf programs to analyze☆91Updated 4 months ago
- Automated upstream mirror for bpftool stand-alone build.☆495Updated 2 weeks ago
- ☆87Updated this week
- Scaffolding for BPF application development with libbpf and BPF CO-RE☆1,222Updated last week
- The system call intercepting library☆640Updated 3 months ago
- A packet oriented Linux kernel function call tracer☆401Updated last year
- KVM based tiny x86 hypervisor written in pure golang, which can boot Linux☆230Updated 8 months ago
- ☆157Updated 3 months ago
- Quickly build and run kernels inside a virtualized snapshot of your live system☆544Updated this week
- Dectect syscall hooking using eBPF☆151Updated last year