Skip to content
View blackye's full-sized avatar
💭
I may be slow to respond.
💭
I may be slow to respond.
  • Tencent

Block or report blackye

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
24 stars written in C
Clear filter

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

C 22,073 4,031 Updated Dec 22, 2025

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.

C 20,073 1,171 Updated Oct 26, 2025

Small and highly portable detection tests based on MITRE's ATT&CK.

C 11,399 3,033 Updated Dec 22, 2025

The pattern matching swiss knife

C 9,291 1,544 Updated Nov 26, 2025

Official git repo for iodine dns tunnel

C 7,510 570 Updated Sep 4, 2025

Defeating Windows User Account Control

C 7,213 1,404 Updated Dec 14, 2025

dperf: High-Performance Network Load Testing Tool Based on DPDK

C 5,510 553 Updated Nov 10, 2025

upstream mirror

C 4,918 1,009 Updated Dec 22, 2025

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

C 4,823 606 Updated Nov 8, 2023

Open Source Deep Packet Inspection Software Toolkit

C 4,287 963 Updated Dec 20, 2025

nginx-1.9.2源码通读分析注释,带详尽函数中文分析注释以及相关函数流程调用注释,最全面的nginx源码阅读分析中文注释,更新完毕

C 4,209 1,249 Updated Jul 26, 2021

A Redis HTTP interface with JSON output

C 2,938 310 Updated Mar 14, 2025

The first open-source DDoS protection system

C 1,560 246 Updated Nov 5, 2025

Process-aware, eBPF-based tcpdump

C 1,164 61 Updated Dec 15, 2025

Hide a process under Linux using the ld preloader (https://sysdig.com/blog/hiding-linux-processes-for-fun-and-profit/)

C 1,114 323 Updated Aug 2, 2019

Linux LD_PRELOAD rootkit (x86 and x86_64 architectures)

C 969 196 Updated Dec 11, 2020

Fast Python Bloom Filter using Mmap

C 747 135 Updated Nov 4, 2019

QNSM is network security monitoring framework based on DPDK.

C 527 188 Updated Sep 27, 2021

Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)

C 303 56 Updated Nov 30, 2024

a PoC for Linux to get around agents that log commands being executed, without root privilege. Linux低权限模糊化执行的程序名和参数,避开基于execve系统调用监控的命令日志

C 243 39 Updated May 8, 2019

linux rootkit

C 162 32 Updated Feb 12, 2018

dpdk infrastructure for software acceleration. Currently working on RX and ACL pre-filter

C 90 43 Updated Mar 10, 2021

Junk code - needless to explain

C 77 27 Updated Sep 10, 2021

suspicious flow checker for http and dns

C 1 1 Updated Oct 12, 2017