0x.Tools: X-Ray vision for Linux systems
-
Updated
Nov 4, 2025 - Python
eBPF is a technology that can run sandboxed programs in a privileged context such as the operating system kernel.
It is used to safely and efficiently extend the capabilities of the kernel at runtime without requiring to change kernel source code or load kernel modules.
0x.Tools: X-Ray vision for Linux systems
Monitor Network Traffic Per Executable, Beautifully Visualized
Dump unix domain socket traffic with bpf
Performance visualisation tools
The first open-source eBPF sandbox for Python (macOS/Linux): Secure libraries, block RCE, and enforce precise syscall control. Dive into module & package-level security now.
Demos for Pixie: github.com/pixie-io/pixie
Monitor DNS queries by host processes using eBPF!
与 eBPF 相关的精选项目的中文清单 (自动翻译自 https://github.com/zoidyzoidzoid/awesome-ebpf)
🐝 Ransomware Detection using Machine Learning with eBPF for Linux.
Real-time monitoring of KVM/Qemu VMs
[Deplicated] Now we have more sophisticated (and compact) implementation in ipftrace2 repository. Please check it as well.
Threat-informed defense for cloudnative: Reference Implementation of a so-called Honeycluster - The detection capabilities can also be used as a SOC
eBPF-Based NFS Telemetry Exporter for Kubernetes
Created by Alexei Starovoitov, Daniel Borkmann
Released 2014