eBPF topic
eBPF is a technology that can run sandboxed programs in a privileged context such as the operating system kernel. It is used to safely and efficiently extend the capabilities of the kernel at runtime without requiring to change kernel source code or load kernel modules.
ilogtail
Fast and Lightweight Observability Data Collector
eBPF-Guide
eBPF (extended Berkeley Packet Filter) Guide. Learn all about the eBPF Tools and Libraries for Security, Monitoring , and Networking.
surftrace
surftrace is a tool that allows you to surf the linux kernel
lockc
Making containers more secure with eBPF and Linux Security Modules (LSM)
libs
libsinsp, libscap, the kernel module driver, and the eBPF driver sources
bpf-examples
Making eBPF programming easier via build env and examples
bpflock
bpflock - eBPF driven security for locking and auditing Linux machines
tcptracer-bpf
eBPF program using kprobes to trace TCP events without run-time compilation dependencies
deepflow
:sparkles: Zero-code distributed tracing and profiling, observability via eBPF :rocket: