Skip to content
ErenAri/Aegis-BPF
Network Security
A kernel‑level eBPF runtime security agent for Linux that enforces file‑deny and network‑deny rules via LSM hooks.
C++
·
Latest v0.8.0 · 10d ago
Security brief →
Features
-
Kernel‑level blocking of file opens using BPF LSM hooks
-
Inode‑based (device:inode) and path‑based deny rules with OverlayFS copy‑up propagation
-
Dual‑stack network policy supporting IPv4/IPv6 CIDR, port, and IP:port denies
Review required
v0.8.0
New feature
·
Auth
RBAC
Dependencies
Ed25519 signing, CEF format, rule library, BTFhub download
Review required
v0.7.0
Mixed
·
Auth
RBAC
Breaking upgrade
Policy translation, Helm updates, Agent config
Review required
v0.6.0
New feature
·
Auth
RBAC
Hook fix + simulation + CEF + packaging
Review required
v0.5.1
Maintenance
·
Dependencies
Routine maintenance and dependency updates.
Review required
v0.5.0
New feature
·
Auth
RBAC
Workload selector + rule actions + console
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Languages
C++
·
Shell
·
C
View on GitHub
Alternative to
Falco
Tracee
Tetragon
KubeArmor
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for ""
⌘K to open
↑↓ navigate
⏎ open