{"repo":"ErenAri/Aegis-BPF","free":true,"listed":false,"github":"https://github.com/ErenAri/Aegis-BPF","clone":"git clone https://github.com/ErenAri/Aegis-BPF.git","description":"Deterministic Linux runtime enforcement with eBPF LSM: block file/network operations before syscalls complete.","language":"C","stars":18,"topics":["bpf","bpf-lsm","cloud-native-security","container-security","ebpf","helm","incident-response","kubernetes-security","linux-kernel","linux-security"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"AegisBPF AegisBPF is an eBPF-based runtime security agent that monitors and blocks unauthorized file and network activity using Linux Security Modules (LSM). It provides kernel-level enforcement for file deny rules plus outbound and selected inbound network deny surfaces, with an explicit audit-only fallback when enforce-capable hooks are unavailable. Positioning AegisBPF is an enforcement-first eBPF runtime security engine and emerging LSM control plane for Linux/Kubernetes workloads. Compared with detect-first tools such as Falco and Tracee, and general eBPF observability/enforcement systems such as Tetragon, AegisBPF specializes in BPF-LSM -EPERM prevention, IMA-backed exec identity, OverlayFS copy-up handling, dual-stack CIDR network deny, cgroup-scoped policy, and auditable kernel/security posture evidence. Where it fits on the runtime-security map: Features - Kernel-level blocking - Uses BPF LSM hooks to block file opens before they complete - Inode-based rules - Block by device:inode for reliable identification across renames - Path-based rules - Block by file path for human-readable policies - OverlayFS copy-up propagation - LSM inode copy up hook detects when denied lower-layer inodes are promoted to the upper layer (containers/overlay-on-overlay) and propagates the deny rule to the new inode - Dual-stack network policy - Deny IPv4/IPv6 exact IP, CIDR, port, and IP:port rules in kernel hooks - Full socket lifecycle coverage - connect() , bind() , port-oriented listen","default_branch":null,"files":null,"tree":[],"storefront":"/r/ErenAri","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ErenAri/Aegis-BPF/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}