DEV Community

#ebpf

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
What Polling, auditd, and eBPF Can See Through Linux RMM Agents

What Polling, auditd, and eBPF Can See Through Linux RMM Agents

Comments
6 min read
I wrote a new Elastic detection rule to catch eBPF rootkits compiling on-host 🛡️

I wrote a new Elastic detection rule to catch eBPF rootkits compiling on-host 🛡️

Comments 1
2 min read
eBPF-First SLO-Driven Autoscaling for Reliable Systems

eBPF-First SLO-Driven Autoscaling for Reliable Systems

Comments
4 min read
Your Antivirus Only Watches. Mine Kills: Building a Detect-and-Respond Agent in Rust + eBPF

Your Antivirus Only Watches. Mine Kills: Building a Detect-and-Respond Agent in Rust + eBPF

Comments
3 min read
Detecting ransomware with eBPF in Rust

Detecting ransomware with eBPF in Rust

Comments
4 min read
Part 1: Least-privilege Kubernetes, generated from what eBPF saw

Part 1: Least-privilege Kubernetes, generated from what eBPF saw

Comments
10 min read
Catching ransomware with eBPF: what execve/openat tracing taught me about false positives

Catching ransomware with eBPF: what execve/openat tracing taught me about false positives

Comments
2 min read
eBPF verifier limits are a design constraint: what CO-RE field offsets and bounded loops taught me

eBPF verifier limits are a design constraint: what CO-RE field offsets and bounded loops taught me

Comments
3 min read
eBPF on Linux — kprobe vs fentry: Hooking Internals & What Production Observability Misses

eBPF on Linux — kprobe vs fentry: Hooking Internals & What Production Observability Misses

Comments
7 min read
Sysmon vs auditd vs eBPF: What Each One Actually Sees

Sysmon vs auditd vs eBPF: What Each One Actually Sees

Comments
9 min read
eBPF in Kubernetes 2026: From Kernel Feature to Standard Infrastructure

eBPF in Kubernetes 2026: From Kernel Feature to Standard Infrastructure

1
Comments 1
4 min read
I built an eBPF ransomware detector in Rust

I built an eBPF ransomware detector in Rust

Comments
4 min read
field-cage: a local-first alternative for GitHub Actions egress control

field-cage: a local-first alternative for GitHub Actions egress control

1
Comments
5 min read
Kubernetes: iptables is empty after migrating to Cilium — what to look at next

Kubernetes: iptables is empty after migrating to Cilium — what to look at next

6
Comments 2
22 min read
A Differential Test Harness for Native vs. Generic XDP: Methodology and Baseline

A Differential Test Harness for Native vs. Generic XDP: Methodology and Baseline

Comments
9 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.