{"repo":"trailofbits/ebpfpub","free":true,"listed":false,"github":"https://github.com/trailofbits/ebpfpub","clone":"git clone https://github.com/trailofbits/ebpfpub.git","description":"ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.","language":"C++","stars":125,"topics":["security","monitoring","ebpf","llvm","tracing","tracepoints","bpf"],"license":"Apache-2.0","category":"analytics","readme_excerpt":"ebpfpub ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes. - - CI Status Building Prerequisites A recent libc++ or stdc++ library, supporting C++17 CMake = 3.16.2. A pre-built binary can be downloaded from the CMake's download page. Linux kernel = 4.18 (Ubuntu 18.10, CentOS 8, Red Hat Enterprise Linux 8). Test for the support: grep BPF /boot/config- uname -r and check the output for CONFIG BPF=y and CONFIG BPF SYSCALL=y The package libz-dev , needed during linking. Optional, but highly recommended: download and install the osquery-toolchain (see below). This should work fine on any recent Linux distribution. The binaries generated with this toolchain are portable and can be deployed on any distro = CentOS 6/Ubuntu 16.04 If not using the osquery-toolchain (if building with the system toolchain): Clang and the C++ library must both support C++17 . Recent distributions should be compatible (tested on Arch Linux, Ubuntu 19.10 and above). A recent Clang/LLVM installation (8.0 or better), compiled with BPF support. Test for the support: llc --version grep bpf and check that BPF is listed as a registered target. Please note that LLVM itself must be compiled with libc++ when enabling the EBPF COMMON ENABLE LIBCPP option, since ebfpub will directly link against the LLVM libraries. The packages llvm-devel (for LLVMConfig.cmake files), llvm-static (for additional LLVM libraries), and ncurses-devel (for libtinfo ) Installing the osquer","default_branch":null,"files":null,"tree":[],"storefront":"/r/trailofbits","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/trailofbits/ebpfpub/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}