eBPF-based Networking, Security, and Observability
Ebpf GitHub Repositories
Explore popular GitHub repositories tagged “ebpf”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
APM, Application Performance Monitoring System
The container platform tailored for Kubernetes multi-cloud, datacenter, and edge management ⎈ 🖥 ☁️
Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.
eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.
High-level tracing language for Linux
Cloud Native Runtime Security
Web-based Traffic and Cybersecurity Network Traffic Monitoring
ebpf-go is a pure-Go library to read, modify and load eBPF programs and attach them to various hooks in the Linux kernel.
Coroot is an open-source observability and APM tool with AI-powered Root Cause Analysis. It combines metrics, logs, traces, continuous profiling, and SLO-based alerting with predefined dashboards and inspections.
Cloud native networking and network security
Instant Kubernetes-Native Application Observability
eBPF-based Linux high-performance transparent proxy solution.
A curated list of awesome projects related to eBPF.
Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes troubleshooting more efficient.
Continuous profiling for analysis of CPU and memory usage, down to the line number and throughout time. Saving infrastructure cost, improving performance, and increasing reliability.
eBPF-based Security Observability and Runtime Enforcement
Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.
Aya is an eBPF library for the Rust programming language, built with a focus on developer experience and operability.
Linux Runtime Security and Forensics using eBPF
Hubble - Network, Service & Security Observability for Kubernetes using eBPF
eBPF Developer Tutorial: Learning eBPF Step by Step with Examples
Packet, where are you? -- eBPF-based Linux kernel networking debugger
Distributed tracing without code changes. 🚀 Instantly monitor any application using OpenTelemetry and eBPF
Perforator is a cluster-wide continuous profiling tool designed for large data centers
The production-scale datacenter profiler (C/C++, Go, Rust, Python, Java, NodeJS, .NET, PHP, Ruby, Perl, ...)
eBPF distributed networking observability tool for Kubernetes
PcapPlusPlus is a multiplatform C++ library for capturing, parsing and crafting of network packets. It is designed to be efficient, powerful and easy to use. It provides C++ wrappers for the most popular packet processing engines such as libpcap, Npcap, WinPcap, DPDK, AF_XDP and PF_RING.
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF
An open source real-time network topology and protocols analyzer