Skip to content
View lichengfxf's full-sized avatar

Block or report lichengfxf

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
37 stars written in C
Clear filter

Linux kernel source tree

C 228,307 61,558 Updated Apr 12, 2026

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

C 22,338 4,043 Updated Apr 12, 2026

The systemd System and Service Manager

C 16,203 4,438 Updated Apr 12, 2026

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

C 15,106 1,606 Updated Apr 12, 2026

Kernel source tree for Raspberry Pi-provided kernel builds. Issues unrelated to the linux kernel should be posted on the community forum at https://forums.raspberrypi.com/

C 12,763 5,387 Updated Apr 10, 2026

Capstone disassembly/disassembler framework for ARM, ARM64 (ARMv8), Alpha, BPF, Ethereum VM, HPPA, LoongArch, M68K, M680X, Mips, MOS65XX, PPC, RISC-V(rv32G/rv64G), SH, Sparc, SystemZ, TMS320C64X, T…

C 8,657 1,670 Updated Apr 10, 2026

带网络功能的伪全息透明显示桌面站

C 6,613 1,266 Updated Oct 29, 2023

tinyproxy - a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems

C 5,788 742 Updated Apr 3, 2026

eBPF-based Security Observability and Runtime Enforcement

C 4,563 528 Updated Apr 10, 2026

Packet, where are you? -- eBPF-based Linux kernel networking debugger

C 3,725 224 Updated Apr 12, 2026

🔥 ByteHook is an Android PLT hook library which supports armeabi-v7a, arm64-v8a, x86 and x86_64.

C 2,464 385 Updated Feb 28, 2026

🔥 ShadowHook is an Android inline hook library which supports thumb, arm32 and arm64.

C 2,263 385 Updated Feb 28, 2026

GNU Libc - Extremely old repo used for research purposes years ago. Please do not rely on this repo.

C 1,968 959 Updated Aug 24, 2018

bpf 学习仓库

C 1,498 341 Updated Apr 30, 2022

Expanded version of the Espressif ESP webcam

C 1,494 383 Updated Dec 6, 2024

Patching and hooking the Linux kernel with only a stripped Linux kernel image.

C 1,297 312 Updated Mar 30, 2026

Tool for injecting a shared object into a Linux process

C 1,221 254 Updated Feb 23, 2022

https://gitlab.com/samba-team/samba is the Official GitLab mirror of https://git.samba.org/samba.git -- Merge requests should be made on GitLab (not on GitHub)

C 1,080 472 Updated Apr 10, 2026

Hook function calls by replacing PLT(Procedure Linkage Table) entries.

C 878 181 Updated Oct 5, 2025

Hook function calls by inserting jump instructions at runtime

C 726 112 Updated Sep 28, 2025

Library for injecting a shared library into a Linux or Windows process

C 615 118 Updated Sep 27, 2025

Kernel-Mode Driver that loads a dll into every new created process that loads kernel32.dll module

C 420 67 Updated Sep 9, 2018

Linux Kernel hooking engine (x86)

C 391 58 Updated Oct 14, 2025

极客时间专栏《eBPF 核心技术与实战》案例

C 376 117 Updated Feb 24, 2026

Android内联hook框架

C 339 92 Updated Jan 8, 2020

libsinsp, libscap, the kernel module driver, and the eBPF driver sources

C 305 184 Updated Apr 9, 2026

Build an .so file to automatically do the android_native_hook work. Supports ARM64 ! With this, tools like Xposed can do android native hook.

C 287 84 Updated Oct 3, 2018

Extremely fast and lightweight file manager

C 231 41 Updated Feb 3, 2026

hook or replace arbitary linux/FreeBSD kernel functions in runtime, supporting arm32, arm64, x86, x86_64, riscv

C 221 45 Updated Mar 6, 2026

Exploit tool implemented using ebpf.

C 212 30 Updated Jun 4, 2024
Next