Sept. 6, 2023, 6:33 p.m. | Black Hat

Black Hat www.youtube.com

Extended Berkeley Packet Filter (eBPF) is a technology that provides capabilities to programmers seeking to make use of kernel layer performance and functionality. Fundamentally, eBPF allows users to load programs into kernel space and attach them to hook points. This allows for loading kernel code at runtime without needing to modify the kernel source code itself or develop a kernel module.

eBPF programs are written in a high-level language and then compiled into assembly-like bytecode.....

By: Juan José López Jaimez …

alice berkeley packet filter capabilities code ebpf extended berkeley packet filter filter kernel lessons learned packet performance points runtime space technology

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC