Skip to content
87

Awesome eBPF

A curated list of awesome projects related to eBPF.

5.2k stars444 forks237 entriesLast push Sep 14, 2026 (16 days ago)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Reference Documentation >eBPF Essentials

ebpf.io

A gateway to discover all the basics of eBPF, including a listing of the main related projects and of community resources.

In 2 lists

Cilium's BPF and XDP Reference Guide

In-depth documentation about most features and aspects of eBPF.

In 2 lists

docs.ebpf.io

Providing technical documentation for eBPF.

In 2 lists

Reference Documentation >Kernel Documentation

BPF Documentation

Index for BPF-related documentation coming with the Linux kernel.

linux/Documentation/networking/filter.rst

eBPF specification (somewhat outdated; information should still be valid, but not exhaustive).

BPF Design Q&A

Frequently Asked Questions on the decisions behind the BPF infrastructure.

HOWTO interact with BPF subsystem

Frequently Asked Questions about contributing to eBPF development.

Reference Documentation >Manual Pages

bpf(2)

Manual page about the bpf() system call, used to manage BPF programs and maps from userspace.

tc-bpf(8)

Manual page about using BPF with tc, including example commands and samples of code.

bpf-helpers(7) man page

Description of the in-kernel helper functions forming the BPF standard library.

Reference Documentation >Other

RFC 9669 BPF Instruction Set Architecture

IETF specification for eBPF

Jesper Dangaard Brouer's documentation

Work in progress, contributions welcome.

bpf.h and you...

Contextually speaking...

BPF Verifier Overview

List of BPF features per kernel version

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

In 5 listsDetails

A List of Research Papers

Articles and Presentations >Generic eBPF Presentations and Articles

A brief introduction to XDP and eBPF

An accessible introduction providing context, history, and details about the functioning of eBPF.

Part 1: Introduction

Part 2: Machine & Bytecode

Ferris Ellis's blog posts about eBPF

They have a few posts about eBPF:

Part 1: Past, Present, and Future

Part 2: Syscall and Map Types

List of BPF features per kernel version

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

In 5 listsDetails

The BSD Packet Filter

An introduction mostly covering the tracing aspects.

BPF: tracing and more

An introduction mostly covering the tracing aspects.

Linux BPF Superpowers

An introduction mostly covering the tracing aspects, first part with flame graphs.

IO Visor

Also introduces IO Visor project.

BPF -- in-kernel virtual machine

Presentation by the author of eBPF.

Extending extended BPF

A blog post from 2014 on the development of BPF and demonstrating what can be done with it, using an example of stateful socket filtering by attaching an eBPF program to a socket.

A Tour of Program Types

A description of all existing hooks for BPF program types, and of their interest.

BPF helper functions

A review of the kernel functions that can be called from within eBPF programs.

Communicating with Userspace

How BPF communicates with userspace - BPF maps, perf events, bpf_trace_printk.

Building BPF Programs

Setting up your environment to build BPF programs.

The BPF Bytecode and the BPF Verifier

How does BPF ensure that programs are safe?

Using BPF to do Packet Transformation

One eBPF usage about packet transformation.

Linux Kernel Observability through eBPF

A blog post covering the basics of eBPF as well as code samples in Go on how to build and load a minimal eBPF program into the kernel.

eBPF - From a Programmer's Perspective

A short paper describing the fundamentals of eBPF and how to get started with writing eBPF programs.

Cloudflare's blog posts on eBPF

Different blog posts about networking use cases and low-level aspects of eBPF.

Linux Extended BPF (eBPF) Tracing Tools

An in-depth collection of information around examples of performance analysis tools using eBPF. Contains also a section at the end of the page about other resources.

Beginner's guide to eBPF

A set of live-coding talks and the accompanying code examples, introducing eBPF programming using a variety of libraries and program types.

ebpf.io blog

Links to many community blogs posts.

Articles and Presentations >BPF Internals

eBPF and XDP walkthrough and recent (2017) updates

Advanced programmability and recent updates with tc's cls_bpf

Details on eBPF, its use for tunneling and encapsulation, direct packet access, and more.

cls_bpf/eBPF updates since netdev 1.1

Part of this tc workshop.

On getting tc classifier fully programmable with cls_bpf

Introduction to eBPF, including several features (map management, tail calls, verifier). The full paper is also available here.

Linux tc and eBPF

Linux Networking Explained

Linux networking internals, with a part about eBPF.

Articles and Presentations >Kernel Tracing

Full-system dynamic tracing on Linux using eBPF and bpftrace

A detailed introduction to tracing with eBPF, from listing the available trace points to running bpftrace programs.

Meet-cute between eBPF and Kernel Tracing

Kprobes, uprobes, ftrace.

Linux Kernel Tracing

Systemtap, Kernelshark, trace-cmd, LTTng, perf-tool, ftrace, hist-trigger, perf, function tracer, tracepoint, kprobe/uprobe, and more.

Articles and Presentations >XDP

The eXpress Data Path

A very accessible introduction to XDP, providing sample code to show how to process packets.

Work-in-progress documentation for XDP

Cilium's BPF and XDP Reference Guide

In-depth documentation about most features and aspects of eBPF.

In 2 lists

XDP Project overview

eXpress Data Path (XDP)

The first presentation about XDP.

eXpress Data Path

Contains some benchmark results obtained with the mlx4 driver.

XDP − eXpress Data Path, Intro and future use-cases

Linux Kernel's fight against DPDK. Future plans (as of this writing) for XDP and comparison with DPDK.

Network Performance Workshop

Additional hints about XDP internals and expected evolution.

XDP – eXpress Data Path, Used for DDoS protection

Details and use cases about XDP, with benchmark results, and code snippets for benchmarking as well as for basic DDoS protection with eBPF/XDP (based on an IP blacklisting scheme).

Memory vs. Networking, Provoking and fixing memory bottlenecks

Advanced details about current memory issues faced by XDP developers.

XDP for the Rest of Us

How to get started with eBPF and XDP for normal humans. Also summarized by Julia Evans on her blog.

XDP now with REDIRECT

Update on XDP, and in particular on the redirect actions.

XDP workshop -- Introduction, experience, and future development (Video)

High Speed Packet Filtering on Linux

About packet filtering on Linux, DDoS protection, packet processing in the kernel, kernel bypass, XDP and eBPF.

How to drop 10 million packets per second

Cloudflare's blog post talking about their move to using XDP for packet filtering.

Articles and Presentations >AF_XDP

AF_XDP

Kernel documentation on the AF_XDP address family.

Fast Packet Processing in Linux with AF_XDP

Articles and Presentations >bpfilter

Why is the kernel community replacing iptables with BPF?

A blog post by Cilium on the motivations behind eBPF and bpfilter, with a couple examples and links to other projects using eBPF and bpfilter.

In 2 lists

bpfilter: Linux firewall with eBPF sauce

Slides from a talk by Quentin Monnet with a background on eBPF and comparing bpfilter to iptables.

In 2 lists

Articles and Presentations >BTF

BPF Type Format (BTF)

Kernel documentation about BTF, explaining how to use it.

Enhancing the Linux kernel with BTF type information

A description of the work done with BTF to provide debugging information for BPF programs.

What is BTF (BPF Type Format)

A community-authored newsletter enriched with useful code illustrations and hands-on examples.

Articles and Presentations >cBPF

The BSD Packet Filter: A New Architecture for User-level Packet Capture

The original paper about (classic) BPF.

The FreeBSD manual page about BPF

Linux' packet mmap(2), BPF, and Netsniff-NG

tc and cls bpf: lightweight packet classifying with BPF

Introducing Cloudflare's BPF Tools

Usage of BPF bytecode with the xt_bpf module for iptables.

Libpcap filters syntax

Articles and Presentations >Hardware Offload

eBPF/XDP hardware offload to SmartNICs

Hardware offload for eBPF with TC or XDP (Linux kernel 4.9+), introduced by Netronome.

Comprehensive XDP offload---Handling the edge cases

An update on the topic above.

hBPF - eBPF in hardware

An eBPF CPU written for FPGAs.

OpenCSD eBPF SSD offloading

Computational Storage simulation (QEMU) platform with FUSE LFS filesystem for Zoned Namespaces NVMe SSDs using uBPF for compute kernel offloading, all in userspace.

Delilah: eBPF-offload on Computational Storage

Delilah is a Computational Storage Processor (CSP) built for eBPF offload to storage devices.

Tutorials

eBPF Party

Browser-based playground to learn, write, compile, and run eBPF programs.

List of BPF features per kernel version

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

In 5 listsDetails

Building BPF applications with libbpf-bootstrap

Helps generate minimal or advanced templates to bootstrap your own applications (kernel side and user space management for maps and programs) with features like CO-RE, global variables, and ring buffer.

How I ended up writing opensnoop in pure C using eBPF

A thorough walk-through of how to write eBPF programs, first using only bpf() syscall, and then libbpf library, with reproducible code examples.

Linux Tracing Workshops Materials

Involves the use of several BPF tools for tracing.

In 2 lists

Tracing a packet journey using Linux tracepoints, perf and eBPF

Troubleshooting ping requests and replies with perf and bcc programs.

Open NFP platform

Operated by Netronome: some tutorials for network-related eBPF use cases, including an eBPF Offload Starting Guide.

XDP for the Rest of Us

How to get started with eBPF and XDP for normal humans. Also summarized by Julia Evans on her blog.

XDP for the Rest of Us

Second edition, with new contents.

XDP Hands-On Tutorial

A progressive (three levels of difficulty) tutorial to learn how to process packets with XDP.

In 2 lists

All your tracing are belong to BPF

A step-by-step walkthrough to integrate tracing capabilities in your C++ applications with the LLVM libraries.

Firewalling with BPF/XDP: Examples and Deep Dive

A simple guide to build basic firewalls with TC and XDP.

A Deep Dive into eBPF: Writing an Efficient DNS Monitoring.

A detailed explanation of methods used to capture DNS requests at the socket filter layer.

eBPF Developer Tutorial - Learn eBPF by examples

Start with eBPF basics and progress to advanced topics using 20+ hands-on tutorials and examples. Covers performance, networking, and security with libbpf and CO-RE. Available in Chinese and English.

Catch Performance Regressions in eBPF

A step-by-step guide to benchmarking both the client and kernel eBPF code written in Rust.

Loops and Iterators in eBPF

Newsletter about all the ways to loop and iterate in eBPF.

What Insights Can eBPF Provide into Real-Time SSL/TLS Encrypted Traffic and How?

A step-by-step guide how eBPF can observe encrypted network traffic.

Can eBPF Detect Redis Message Patterns Before They Become Problems?

A step-by-step guide how eBPF can observe Redis communication between client and server.

Transparent Proxy Implementation using eBPF and Go

A step-by-step guide on how to implement a transparent proxy using eBPF.

eBPF-Powered Load Balancing

Learn how eBPF can infer custom load-balancing for services listening on the same port, through the SO_REUSEPORT TCP option.

Unit Testing eBPF Programs

Learn how you can unit test your eBPF programs using libbpf.

Accelerating Local Socket Communication using eBPF

Learn how eBPF can speed-up local socket communication up to 30%.

Writing a basic continuous profiler

A step-by-step guide to write an appliation continuous profiler leveraging the eBPF instrumentation, with a complete project as a reference.

Inspektor Gadget - Hello world gadget

An introductory guide to writing image-based eBPF gadgets and sharing them via OCI registries.

Inspektor Gadget - Hello world gadget with Wasm

An introductory guide to writing image-based eBPF gadgets and performing post-processing with WASM.

ebpf.io labs

List of community developed labs.

Examples

linux/samples/bpf/

In the kernel tree: some sample eBPF programs.

linux/tools/testing/selftests/bpf

In the kernel tree: Linux BPF selftests, with many eBPF programs.

prototype-kernel/kernel/samples/bpf

Jesper Dangaard Brouer's prototype-kernel repository contains some additional examples that can be compiled outside of kernel infrastructure.

iproute2/examples/bpf/

Some networking programs to attach to the TC interface.

Netronome sample network applications

Provides basic but complete examples of eBPF applications also compatible with hardware offload.

List of BPF features per kernel version

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

In 5 listsDetails

MPLSinIP sample

A heavily commented sample demonstrating how to encapsulate and decapsulate MPLS within IP. The code is commented for those new to BPF development.

ebpf-samples

A collection of compiled (as ELF object files) samples gathered from several projects, primarily intended to serve as test cases for user space verifiers.

ebpf-kill-example

A fully documented and tested example of an eBPF probe that logs all force-kills and prints them out in user-space.

redbpf examples

Example programs for using RedBPF to write eBPF programs in Rust.

XDP/TC-eBPF example

Program that uses XDP/TC-eBPF to provide statefull firewalling and socket redirection.

eBPF Workflow: Tools and Utilities >bcc

List of BPF features per kernel version

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

In 5 listsDetails

eBPF Workflow: Tools and Utilities >iproute2

iproute2

Package containing tools for network management on Linux. In particular, it contains tc, used to manage eBPF filters and actions, and ip, used to manage XDP programs. Most of the code related to BPF is in lib/bpf.c.

iproute2-next

The development tree, synchronised with net-next.

eBPF Workflow: Tools and Utilities >LLVM

LLVM

Contains several tools used in eBPF workflows. Snapshots of the latest versions for Ubuntu/Debian can be retrieved from here.; clang is used to compile C to eBPF object file under the ELF format (clang v3.7.1+). The BPF backend was added with this commit.; llvm-objdump is used to dump the content…

In 3 lists

eBPF Workflow: Tools and Utilities >libbpf

libbpf

A C library used for handling BPF objects (programs and maps), and manipulating ELF object files containing them. It is shipped with the kernel and mirrored on GitHub.

libbpf-bootstrap

Scaffolding for BPF application development with libbpf and BPF CO-RE.

eBPF Workflow: Tools and Utilities >Go libraries

cilium/ebpf

Pure-Go library to read, modify and load eBPF programs and attach them to various hooks in the Linux kernel.

In 5 listsDetails

libbpfgo

eBPF library for Go, powered by libbpf.

eBPF Workflow: Tools and Utilities >Aya

aya

A pure Rust library for writing, loading, and managing eBPF objects, with a focus on developer experience and operability. It supports writing eBPF programs in Rust and distributing library code over crates.io to share it between eBPF programs. Aya does not depend on libbpf.

In 2 lists

aya-template

Templates for writing BPF applications in Aya that can be used with cargo generate.

eBPF Workflow: Tools and Utilities >zbpf

zbpf

A pure Zig framework for writing cross platform eBPF programs, powered by libbpf and Zig toolchain.

In 2 lists

eBPF Workflow: Tools and Utilities >eunomia-bpf

eunomia-bpf

A compilation framework and runtime library to build, distribute, dynamically load, and run CO-RE eBPF applications in multiple languages and WebAssembly. It supports writing eBPF kernel code only (to build simple CO-RE libbpf eBPF applications), writing the kernel part in both BCC and libbpf…

eBPF Workflow: Tools and Utilities >bpftool and Other Tools from the Kernel Tree

bpftool

Also some other tools in the kernel tree, under linux/tools/net/ for versions earlier than 4.15, or linux/tools/bpf/ after that:

bpf_asm

A minimal cBPF assembler.

bpf_dbg

A small debugger for cBPF programs.

bpf_jit_disasm

A disassembler for both BPF flavors and could be highly useful for JIT debugging.

eBPF Workflow: Tools and Utilities >User Space eBPF

uBPF

Written in C. Contains an interpreter, a JIT compiler for x86_64 architecture, an assembler and a disassembler.

A generic implementation

With support for FreeBSD kernel, FreeBSD user space, Linux kernel, Linux user space and macOS user space. Used for the VALE software switch's BPF extension module.

rbpf

Written in Rust. Interpreter for Linux, macOS and Windows, and JIT-compiler for x86_64 under Linux.

PREVAIL

A user space verifier for eBPF using an abstract interpretation layer, with support for loops.

wachy

A tracing profiler that aims to make eBPF uprobe-based debugging easier to use. This is done by displaying traces in a UI next to the source code and allowing interactive drilldown analysis.

eBPF Workflow: Tools and Utilities >eBPF on Other Platforms

eBPF for Windows

This project is a work-in-progress that allows using existing eBPF toolchains and APIs familiar in the Linux ecosystem to be used on top of Windows.

In 2 lists

eBPF Workflow: Tools and Utilities >Testing in Virtual Environments

bcc in a Docker container

bpfcompat

Boots real Linux kernels in disposable QEMU/KVM VMs to load- and attach-validate compiled eBPF objects across a multi-distro, multi-architecture kernel matrix, classifying failures (missing BTF, unsupported map/program type, CO-RE relocations); runs as a CI gate and GitHub Action.

Projects Related to eBPF >Networking

OvS Orbit episode (#11), called P4 on the Edge

Related to the former item. Audio interview of John Fastabend by Ben Pfaff, one of the core maintainers of Open vSwitch.

P4_16 backend for eBPF

Cilium

project (GitHub repository) is a technology relying on eBPF and XDP to provide "fast in-kernel networking and security policy enforcement for containers based on eBPF programs generated on the fly". Many presentations available (with overlap):

In 5 listsDetails

Cilium: Networking & Security for Containers with BPF & XDP

Also featuring a load balancer use case

Cilium: Networking & Security for Containers with BPF & XDP

video

Cilium: Fast IPv6 container Networking with BPF and XDP

Cilium: BPF & XDP for containers

BPF & XDP for containers.

In 2 lists

OvS Orbit episode (#4)

Interview of Thomas Graf by Ben Pfaff.

A generic introduction to Cilium

Generic introduction to Cilium.

In 2 lists

A podcast interviewing Thomas Graf

Ivan Pepelnjak interviewing Thomas, October 2016, on eBPF, P4, XDP and Cilium.

Katran

A layer 4 load-balancer based on XDP, open-sourced by Facebook.

XDP in practice: integrating XDP in our DDoS mitigation pipeline

Protection against DDoS with XDP at Cloudflare.

Droplet: DDoS countermeasures powered by BPF + XDP

Protection against DDoS with XDP at Facebook.

DPDK has a poll-mode driver (PMD) based on AF_XDP

CETH for XDP

Common Ethernet Driver Framework for faster network I/O, a technology initiated by Mellanox.

"eBPF and XDP" section of Suricata documentation

SEPTun-Mark-II

Extreme Performance Tuning guide - Mark II.

In 2 lists

A blog post introducing the "capture bypass" feature

The adventures of a Suricate in eBPF land

eBPF and XDP seen from the eyes of a meerkat

Project Calico

Calico is an open source networking and network security solution for containers, virtual machines, and native host-based workloads. Calico's eBPF data plane delivers a low latency, high throughput data plane with a rich network security policy model.

Enabling eBPF data plane with Calico

merbridge

Use eBPF to speed up your Service Mesh. Merbridge replaces iptables rules with eBPF to intercept traffic. It also combines msg_redirect to reduce latency with a shortened datapath between sidecars and services.

In 2 lists

PcapPlusPlus

An open-source C++ library for capturing, parsing and crafting network packets. It features a C++ interface for creating AF_XDP sockets, making it easy to send and receive packets through them.

ApFree WiFiDog

A high performance and lightweight captive portal solution for wireless networks. It leverages eBPF for traffic control and deep packet inspection capabilities, with plans to gradually replace nftables firewall functionality with eBPF-based solutions.

In 2 lists

ipx_wrap

A proof-of-concept IPX implementation for Linux using eBPF.

Projects Related to eBPF >Observability

eXpress Data Path (XDP)

The first presentation about XDP.

DEEP-mon

Helps with measuring power consumption for servers and uses eBPF programs for in-kernel aggregation of data.

pixie

Observability for Kubernetes using eBPF. Features include protocol tracing, application profiling, and support for distributed bpftrace deployments.

In 4 listsDetails

SkyWalking Rover

Apache SkyWalking is an open-source Application Performance Monitoring (APM) platform specially designed for distributed systems with microservices, cloud-native and container-based (Kubernetes) architectures. SkyWalking Rover is an eBPF-based profiler and metrics collector for C, C++, Golang, and…

parca-agent

eBPF based always-on continuous profiler for analysis of CPU and memory usage, down to the line number and throughout time.

rbperf

Sampling profiler and tracer for Ruby.

rstat

Sub-millisecond system monitoring using eBPF tracepoints on sched_switch, sched_process_exit, and sched_process_free, with zero heap allocations in steady state.

Hubble

Network, service and security observability for Kubernetes using eBPF.

In 5 listsDetails

Ingero

eBPF-based GPU causal observability agent. Traces CUDA Runtime and Driver APIs via uprobes and host kernel events via tracepoints to build causal chains explaining GPU latency, with <2% overhead.

In 4 listsDetails

Caretta

Instant Kubernetes service dependency map generated by eBPF, right to a Grafana instance.

In 3 lists

kpod-metrics

eBPF-based pod-level kernel metrics collector for Kubernetes. Exports per-pod CPU, network, memory, syscall, disk I/O, and L7 protocol metrics to Prometheus. BPF programs are defined using a Kotlin DSL instead of C.

DeepFlow

Instant observability for cloud-native and AI applications based on eBPF.

In 2 lists

Coroot

Coroot is an open-source APM and observability tool, a DataDog and NewRelic alternative.

In 3 lists

kyanos

Kyanos is an eBPF-based network issue analysis tool that enables you to capture network requests, such as HTTP, Redis, and MySQL requests.

In 4 listsDetails

eTraceGen

eTraceGen is a Linux telemetry engine built with eBPF and Modern C++ that captures kernel-level events for processes, files, system calls, and network with a modular pipeline for decoding, enrichment, filtering, and JSON output.

Projects Related to eBPF >Security

Falco

A cloud-native runtime security project used as a Kubernetes threat detection engine.

In 5 listsDetails

Sysmon for Linux

A security monitoring tool. It depends on SysinternalsEBPF.

In 3 lists

Red Canary Linux Agent

Red Canary has started to incorporate eBPF to their Linux security sensor.

Tracee

A runtime security and forensics tool for Linux which uses eBPF technology to trace the system and applications at runtime, and analyze collected events to detect suspicious behavioral patterns.

In 5 listsDetails

redcanary-ebpf-sensor

A set of BPF programs that gather security relevant event data from the Linux kernel. The BPF programs are combined into a single ELF file from which individual probes can be selectively loaded, depending on the running operating system and kernel version.

bpflock - Lock Linux machines

An eBPF driven security tool for locking and auditing Linux machines.

In 2 lists

Tetragon

Kubernetes-aware, eBPF-based security observability and runtime enforcement.

In 4 listsDetails

harpoon

Trace syscalls from user-space functions, by using eBPF.

Synapse

Extended detection and response (XDR) with eBPF-powered firewall and proxy, to protect your Linux servers.

BPFJailer

BpfJailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux.

Bombini

An eBPF-based security agent written entirely in Rust using the Aya library and built on LSM (Linux Security Module) BPF hooks.

owLSM

Open source agent that implements a stateful Sigma rules engine focused on monitoring and prevention using eBPF LSM.

Inner Warden

A self-defending security agent for Linux and macOS that uses eBPF with 22 kernel hooks (tracepoints, kprobes, LSM, XDP) via the Aya library for real-time threat detection, automated response, and AI-powered triage.

In 2 lists

Projects Related to eBPF >Linux Scheduler

scx

sched_ext schedulers and tools.

Gthulhu

Gthulhu optimizes cloud-native workloads using the Linux Scheduler Extension for different application scenarios.

Projects Related to eBPF >Tools

ply

A small but flexible open source dynamic tracer for Linux, with features similar to the bcc tools, but with a simpler language inspired by awk and DTrace.

bpftrace

A tool for tracing with its own high-level tracing language. It is flexible enough to be envisioned as a Linux replacement for DTrace and SystemTap.

bpftrace Cheat Sheet

Summary and cheat sheet for programming in bpftrace. Contains information about syntax, probe types, variables and functions.

kubectl trace

A kubectl plug-in for executing bpftrace programs in a Kubernetes cluster.

In 2 lists

inspektor-gadget

A collection tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF.

bpfd

Framework for running BPF programs with rules on Linux as a daemon. Container aware.

BPFd

A distinct BPF daemon, trying to leverage the flexibility of the bcc tools to trace and debug remote targets, and in particular devices running with Android.

adeb

A Linux shell environment for using tracing tools on Android with BPFd.

greggd

System daemon to compile and load eBPF programs into the kernel, and forward program output to socket for metric aggregation.

FUSE

Considers using eBPF.

upf-bpf

An in-kernel solution based on XDP for 5G UPF.

redbpf examples

Example programs for using RedBPF to write eBPF programs in Rust.

ebpf-explorer

A web interface to explore system's maps and programs.

ebpfmon

A TUI (terminal user interface) application for real time monitoring of eBPF programs.

bpfman

An eBPF Manager for Linux and Kubernetes. Includes a built-in program loader that supports program cooperation for XDP and TC programs, as well as deployment of eBPF programs from OCI images.

ptcpdump

A process-aware, eBPF-based tcpdump-like tool.

oryx

A TUI for sniffing network traffic using eBPF on Linux.

In 3 lists

GhostScope

A DWARF-aware eBPF tracer for source-level userspace tracing, with an interactive TUI and a scriptable CLI.

AgentSight

Zero-instrumentation eBPF observability for LLM and coding agents, capturing syscall-level traces (file, network, process) without modifying the agent.

ActPlane

OS-level agent harness that compiles a policy DSL to an in-kernel eBPF engine for labeled information-flow control at the syscall boundary, enforcing constraints across any tool or subprocess.

eBPF in Security

Embrace The Red: Offensive BPF!

A series of posts around the introduction into BPF with a focus to an offensive setting, and also how its misuse can be detected. Posts include discussions on the rootkit capabilities of eBPF, or on which tracing type is needed for different use cases.

eBPF: Block Linux Fileless Payload "Malware" Execution with BPF LSM

Blog post about how BPF can help detection and blocking fileless malware.

Blackhat 2021: With Friends Like eBPF, Who Needs Enemies?

Talk about an eBPF rootkit and how the capabilities of eBPF could be abused. The rootkit was also the object of a talk at Defcon, eBPF, I thought we were friends !.

ebpfkit

A rootkit that leverages multiple eBPF features to implement offensive security techniques.

In 3 lists

ebpfkit-monitor

An utility to statically analyze eBPF bytecode or monitor suspicious eBPF activity at runtime. It was specifically designed to detect ebpfkit.

Bad BPF

A collection of malicious eBPF programs that make use of eBPF's ability to read and write user data in between the usermode program and the kernel.

TripleCross

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

In 6 listsDetails

The Code

linux/include/linux/bpf.h

with linux/include/uapi/bpf.h: definitions related to eBPF, to be used respectively in the kernel and to interface with userspace programs.

linux/include/linux/filter.h

with linux/include/uapi/filter.h: information used to run the BPF programs themselves.

linux/kernel/bpf/

This directory contains most of BPF-related code. In particular, those files are worth of interest:

syscall.c

Different operations permitted by the system call, such as program loading or map management.

core.c

BPF interpreter.

verifier.c

BPF verifier.

linux/net/core/filter.c

Functions and eBPF helpers related to networking (TC, XDP etc.); also contains the code to migrate cBPF bytecode to eBPF (all cBPF programs are translated to eBPF in recent kernels).

linux/kernel/trace/bpf_trace.c

Functions and eBPF helpers related to tracing and monitoring (kprobes, tracepoints, etc.).

linux/net/sched/

and in particular in files act_bpf.c (action) and cls_bpf.c (filter): code related to BPF actions and filters with TC.

linux/kernel/seccomp.c

linux/net/core/dev.c

contains the function dev_change_xdp_fd() that is called through a Netlink command to hook a XDP program to a device, after is has been loaded into the kernel from user space. This function in turns uses a callback from the relevant driver.

Development and Community

The bpf-next tree

BPF patches land in this tree. It is regularly merged into net-next, which is itself merged for each release to Linus' tree.

Kernel documentation

About contributions to BPF.

The netdev mailing list

Mailing list for Linux kernel networking stack development. All patches are sent there for review and inclusion.

XDP-newbies

A mailing list specially dedicated to XDP programming (both for architecture or for asking for help).

The XDP Collaboration Project

A GitHub repository with notes and ideas regarding the future evolutions of XDP.

Other Lists of Resources on eBPF

List of BPF features per kernel version

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

In 5 listsDetails

eXpress Data Path (XDP)

The first presentation about XDP.

Dive into BPF: A List of Reading Material

See category
94

Awesome Mac

jaywcjlove/awesome-mac

 This project is dedicated to collecting high-quality macOS software and organizing them systematically by different categories for easy search and use.

Fresh★ 115k1316 entriesPushed today
91

Open Source Mac Os Apps

serhii-londar/open-source-mac-os-apps

🚀 Awesome list of open source applications for macOS. https://t.me/s/opensourcemacosapps

Fresh★ 51k700 entriesPushed 20 days ago
91

Awesome-Kubernetes

ramitsurana/awesome-kubernetes

A curated list for awesome kubernetes sources :ship::tada:

Fresh★ 16k47 entriesPushed 8 days ago
90

Awesome Nodejs

sindresorhus/awesome-nodejs

:zap: Delightful Node.js packages and resources [BECAUSE OF TOO MUCH SPAM AND LOW-QUALITY SUBMISSIONS, SUBMISSIONS ARE PAUSED TEMPORARILY]

Fresh★ 67k588 entriesPushed 28 days ago
90

Awesome Home Assistant

frenck/awesome-home-assistant

A curated list of amazingly awesome Home Assistant resources.

Fresh★ 8.5k312 entriesPushed 2 days ago
90

Awesome Ios

vsouza/awesome-ios

A curated list of awesome iOS ecosystem, including Objective-C and Swift Projects

Fresh★ 53k1812 entriesPushed 1 month ago