
tetragon
eBPF-based Security Observability and Runtime Enforcement

eBPF-based Security Observability and Runtime Enforcement

eBPF-based runtime security agent for Kubernetes that detects unknown processes and file changes, enforces pre-registered constraints, and automates…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Experimental Decoy Broker


By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

PoC and Detection for CVE-2024-21626

An eBPF detection program for CVE-2022-0847

Anti-Virus for K8s. Protect your Applications running on Kubernetes from malicious attacks with pre-registered source code, runtime processes…