AegisBPF – Deterministic Runtime Enforcement via eBPF LSM
LSM hooks block operations synchronously; most eBPF security tools only alert asynchronously.
Behavioral hidden-cryptominer detector for Linux in eBPF — flags processes talking to mining-pool ports while spoofing kernel-thread names. No signatures, no agent, no cloud. CO-RE portable.
eBPF behavioral detection catches miners spoofing thread names without signature databases.
Linux sysadmins, security engineers, incident responders
Falco · Tracee · CrowdStrike
LSM hooks block operations synchronously; most eBPF security tools only alert asynchronously.
eBPF-based USB sniffer bypasses usbmon entirely using universal URB hooks for zero-setup debugging.
Curated index for kernel docs when docs.kernel.org already has search and navigation.
Kernel-level AI agents on Android, but half-baked security model and unclear differentiation.
Direct eBPF kernel tracing beats slow CLI probing for AI sysadmin tasks.
Rust EDR with eBPF on Linux competes against CrowdStrike and Wazuh.