{"repo":"chriskaliX/Hades","free":true,"listed":false,"github":"https://github.com/chriskaliX/Hades","clone":"git clone https://github.com/chriskaliX/Hades.git","description":"Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)","language":"Rust","stars":306,"topics":["agent","hids","golang","ebpf","netlink","linux","ebpf-sec","runtime-security","security","ebpf-programs"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Hades - eBPF based HIDS English 中文 Hades is a Host-based Intrusion Detection System based on eBPF and netlink(cn proc). Now it's still under development. PRs and issues are welcome! Declaration: This project is based on Tracee and Elkeid. Thanks for these awesome open-source projects. Overview This is a demo backend for now, still under dev Architecture Agent part is mainly based on Elkeid version 1.7. Agent Part Data Analysis Plugins - EDriver - Collector - Eguard - WDriver - NCP - Scanner - Logger Capability ------ EDriver Here are 21 hooks over tracepoints / kprobes / uprobes . The fields are extended just like Elkeid(basically). For details of these hooks. eBPF driver hook details Hook Status & Description ID :----------------------------------------- :------------------------------------ :--- tracepoint/syscalls/sys enter execve ON 700 tracepoint/syscalls/sys enter execveat ON 698 tracepoint/syscalls/sys enter memfd create ON 614 tracepoint/syscalls/sys enter prctl ON(PR SET NAME & PR SET MM) 1020 tracepoint/syscalls/sys enter ptrace ON(PTRACE PEEKTEXT & PTRACE POKEDATA) 1021 kprobe/security socket connect ON 1022 kprobe/security socket bind ON 1024 kprobe/commit creds ON 1011 k(ret)probe/udp recvmsg ON(53/5353 for dns data) 1025 kprobe/do init module ON 1026 kprobe/security kernel read file ON 1027 kprobe/security inode create ON 1028 kprobe/security sb mount ON 1029 kprobe/call usermodehelper ON 1030 kprobe/security inode rename ON 1031 kprobe/security inode link ON 10","default_branch":null,"files":null,"tree":[],"storefront":"/r/chriskaliX","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/chriskaliX/Hades/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}