Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.
-
Updated
Sep 24, 2026 - C
Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.
Process-aware, eBPF-based tcpdump
A high-performance, low-latency XDP Layer-4 TCP full-NAT load balancer built with eBPF. Implements Least-Connections and Weighted Least-Connections scheduling, performs stateful per-flow connection tracking in datapath maps, supports dynamic multi-service VIP and backend management via CLI, includes tooling to test under concurrent connection load
ZFS tools, SMR drive tuning, and USB queue monitoring utilities
Log API calls with eBPF
Next-gen Linux EDR using eBPF. Run C programs in the kernel to detect reverse shell, memory injection and masquerading with zero userland hooks. Backend in Go, Dashboard in React/TypeScript. Mapped to MITRE ATT&Ck.
Open-source Linux endpoint security agent built with Go and eBPF for real-time kernel event monitoring, log streaming, and centralized security visibility.
To associate your repository with the ebpf-go topic, visit your repo's landing page and select "manage topics."