Deterministic Linux runtime enforcement with eBPF LSM: block file/network operations before syscalls complete.
-
Updated
May 19, 2026 - C++
Deterministic Linux runtime enforcement with eBPF LSM: block file/network operations before syscalls complete.
SELinux, IdM, and AAP proof of concept for confining privileged automation and denying kernel exploit surfaces before jobs reach managed RHEL hosts.
A modular Next-Generation Antivirus (NGAV) and Endpoint Detection & Response (EDR) for Linux, leveraging eBPF (LSM) and Rust for memory-safe userland.
Kernel-enforced sandboxing for untrusted processes. Two zero-dependency core tools, one shared profile format, plus an optional BPF-LSM module.
Add a description, image, and links to the bpf-lsm topic page so that developers can more easily learn about it.
To associate your repository with the bpf-lsm topic, visit your repo's landing page and select "manage topics."