Building a Line-Rate Linux Kernel Firewall in Pure Rust with Aya and eBPF/XDP
Volumetric Distributed Denial of Service (DDoS) and transport-layer flooding attacks pose an...
Tag archive
Volumetric Distributed Denial of Service (DDoS) and transport-layer flooding attacks pose an...
Detection is the easy half. This is how an eBPF monitor goes from alert to killing the offending process in the same second - and how it makes sure it can't kill the host while doing it.
Solving Spot GPU Eviction Context Loss with Kernel-Level eBPF Socket Hijacking Running LLM...
If you've been following Linux security, you know that eBPF is a double-edged sword. It's incredible...
Why I stopped trusting CPU and request-count thresholds If your autoscaler still reacts to...
Detecting ransomware with eBPF in Rust Title: Detecting ransomware with eBPF in...
Your container makes about 70 of Linux's 300-odd syscalls. Here's how kguardian works out which 70,...
Lessons from building talus-process-monitor, a Rust + eBPF ransomware detector: per-CPU perf buffers, behavioural pattern matching, and why build systems are a detector's worst enemy.
Writing kernel eBPF programs in a portable way — CO-RE relocation, verifier-friendly loops, amortized map design — from the trenches of talus-process-monitor and its CI verification chain.

This evening I wrote one line, as root, into the Docker Desktop virtual machine on my laptop: #...
This article introduces Alibaba Cloud's OBI for zero-code observability of AI Agents in ACS Agent...
This post first appeared on the ET Ducky blog. I build ET Ducky, an RMM that reads ETW on Windows and...