0x.Tools: X-Ray vision for Linux systems
-
Updated
Nov 25, 2025 - Python
eBPF is a technology that can run sandboxed programs in a privileged context such as the operating system kernel.
It is used to safely and efficiently extend the capabilities of the kernel at runtime without requiring to change kernel source code or load kernel modules.
0x.Tools: X-Ray vision for Linux systems
Dump unix domain socket traffic with bpf
Performance visualisation tools
A Python binding for WinDivert driver
Demos for Pixie: github.com/pixie-io/pixie
Monitor DNS queries by host processes using eBPF!
An eBPF based lock tracer for PostgreSQL
与 eBPF 相关的精选项目的中文清单 (自动翻译自 https://github.com/zoidyzoidzoid/awesome-ebpf)
🐝 Ransomware Detection using Machine Learning with eBPF for Linux.
Real-time monitoring of KVM/Qemu VMs
Kernel-Enforced Install-Time Policies (KEIP): An eBPF/LSM based security tool that detects and blocks malicious network activity during pip install.Kernel-Enforced Install-Time Policies (KEIP): An eBPF/LSM based security tool that detects and blocks malicious network activity during pip install
Created by Alexei Starovoitov, Daniel Borkmann
Released 2014