Giter VIP home page Giter VIP logo

Comments (8)

chriskaliX avatar chriskaliX commented on June 11, 2024 1

后续 todo:

  1. 继续强化 eBPF 学习和实践(包括 osquery 4.6.0 之后的bpf代码, eBPF summit 中 google 的视频等...)
  2. 后续采集模块检测内核版本,优先eBPF,失败回滚到 cn_proc
  3. 内核态 Hook 的继续学习,LSM、kprobe、tracepoint 等多种方案利弊
  4. 跟进 fb 的 eBPF CO-RE,继续学习

from hades.

chriskaliX avatar chriskaliX commented on June 11, 2024

这样嘛,我计划的是:普通机器用netlink,高版本的,例如k8s宿主机上用eBPF

from hades.

chriskaliX avatar chriskaliX commented on June 11, 2024

eBPF刚刚看了一点...我再学一学

from hades.

hz-kelpie avatar hz-kelpie commented on June 11, 2024

这篇是我写的http://mp.weixin.qq.com/s?__biz=MzIxNDI0MDAxNg==&mid=2247485102&idx=1&sn=4283bc4ed98eeb17f2be5eeecd3d98ac&chksm=97abd8d1a0dc51c7586326aae0f4fcd9824fd5996723ee3cf51775fa83a5a021ba7be449ec40&mpshare=1&scene=24&srcid=0929IPe1jsu3a4k44p5Q33d4&sharer_sharetime=1633663521291&sharer_shareid=a5b22c302998234e9325c87eb4673e5e#rd

from hades.

hz-kelpie avatar hz-kelpie commented on June 11, 2024

关于eBPF三种部署方式可以参考 后续一起探索吧

from hades.

chriskaliX avatar chriskaliX commented on June 11, 2024

感谢大哥,我立马开始学习

from hades.

hz-kelpie avatar hz-kelpie commented on June 11, 2024

关注你了 一起学习 我也在找HIDS好的HOOK方式,eBPF你到时候会觉得限制太多,Elkid的 ismod方式风险又太大了

from hades.

chriskaliX avatar chriskaliX commented on June 11, 2024

感谢~我也是这么觉得,Elkeid 的模式,以及我对他驱动模块不是很熟悉(万一报错不会debug就麻烦了)

from hades.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.