Userspace eBPF runtime for Observability, Network, GPU & General Extensions Framework
-
Updated
Sep 18, 2026 - C++
Userspace eBPF runtime for Observability, Network, GPU & General Extensions Framework
Human-friendly cross-platform system call tracing and hooking library based on Frida's Stalker
The lazypoline syscall interposer
The scalable approach to build secure in-process syscall interposers
Wraith is a low-level Rust security sensor that answers a question most tools can't: "is this process being exploited right now?" By focusing entirely on anomalous runtime behavior rather than known signatures or payloads, Wraith detects live exploits and uncovers zero-day vulnerabilities completely in advance of a patch.
This is my implementation of syscalls tracing system and copy on write (COW) mechanism, that I've implemented for xv6 educational kernel
Bedrock ebpf-based file access pattern tracing tool.
syscall trace utility for Linux written in Rust
Private dynamic analysis engine and sandbox for malware research, blue team and DFIR (observation only).
Linux Kernel Runtime Security Observability & Syscall Anomaly Tracer using eBPF
Observe file, network, and process capabilities used while installing or requiring Ruby gems.
A pure Python CLI tool for tracing and analyzing system calls on Linux using strace. Zero dependencies, modular architecture, JSON/TXT reports.
Trace-and-learn containerizer that turns Linux installers into hardened Podman containers.
Rooted Android kernel-boundary tracer for security research.
See what an npm lifecycle script actually did: files touched, processes spawned, network endpoints contacted. Linux + strace.
To associate your repository with the syscall-tracing topic, visit your repo's landing page and select "manage topics."