{"repo":"Mutasem-mk4/procscope","free":true,"listed":false,"github":"https://github.com/Mutasem-mk4/procscope","clone":"git clone https://github.com/Mutasem-mk4/procscope.git","description":"Zero-overhead eBPF process tracer for Linux malware triage and incident response. Traces syscalls, network, and file events per-process without strace overhead.","language":"C","stars":34,"topics":["bpf","ebpf","forensics","golang","linux-security","reverse-engineering","security-tools","cli","container-security","incident-response"],"license":"MIT","category":"security-tools","readme_excerpt":"procscope — eBPF Process Tracer for Linux by Mutasem Kharma (معتصم خرما) Zero-overhead, zero-config eBPF process tracer for Linux. Trace malware behavior, investigate suspicious binaries, and audit container workloads — without strace overhead or the complexity of system-wide EDR daemons. Launch a command under observation — or attach to an existing process — and see what it actually does at runtime: process lifecycle, file activity, network connections, privilege transitions, and more. Designed for: security research, malware triage, incident response, and deep debugging. Not designed for: EDR, SIEM, or whole-system tracing. Quick Start 1-Minute Install (Go 1.26+) Full Installation Guide Usage & Output Formats Features & Capabilities Category Events Details ---------- -------- --------- Process exec, fork, exit Support Matrix Files open, rename, unlink, chmod Support Matrix Network connect, accept, bind, listen Support Matrix Privileges setuid, setgid, ptrace Support Matrix Tech Stack & Requirements - Build from source: Go 1.26+ - Observation: eBPF (CO-RE) - Linux kernel 5.8+ with BTF support. - Root privileges or specific eBPF capabilities. - Architectures: amd64, arm64. See Support Matrix for details. Why procscope? - Zero Config: No complex policies or yaml files. - Focused: Automatically follows forks but stays scoped to your target tree. - Evidence Ready: Generates structured evidence bundles and Markdown reports for IR teams. - Low Overhead: eBPF-powered observation wi","default_branch":null,"files":null,"tree":[],"storefront":"/r/Mutasem-mk4","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Mutasem-mk4/procscope/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}