awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Cybereason-Public avatar

Cybereason-Public/owLSM

0
View on GitHub↗
270 stars·14 forks·C·GPL-2.0·8 viewscybereason-public.github.io/owLSM↗

OwLSM

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

Features

  • Networking and Security - Stateful security monitoring using eBPF LSM.

Star history

Star history chart for cybereason-public/owlsmStar history chart for cybereason-public/owlsm

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with OwLSM

These projects share indexed features with OwLSM. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • aquasecurity/traceeaquasecurity avatar

    aquasecurity/tracee

    4,377View on GitHub↗

    Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho

    Gobpfdockerebpf
    View on GitHub↗4,377
  • bombinisecurity/bombinibombinisecurity avatar

    bombinisecurity/bombini

    51View on GitHub↗

    eBPF Security Monitoring and Sandboxing Agent Based on Aya

    Rust
    View on GitHub↗51
  • cilium/ciliumcilium avatar

    cilium/cilium

    23,806View on GitHub↗

    Cilium is a networking, security, and observability platform for containerized environments that leverages kernel-level data paths to process traffic. By executing programs directly within the Linux kernel, it provides high-performance packet filtering, routing, and load balancing without the need for traditional user-space proxies or context switching. The platform distinguishes itself through identity-based security enforcement, which filters traffic based on service labels rather than volatile IP addresses. It integrates containerized workloads with external physical or virtual infrastruct

    Gobpfcncfcni
    View on GitHub↗23,806
  • alegrey91/harpoonalegrey91 avatar

    alegrey91/harpoon

    177View on GitHub↗

    🔍 Function-level tracing tool for Seccomp profiling, with eBPF

    C
    View on GitHub↗177
Compare all 13 related projects→

Frequently asked questions

What does cybereason-public/owlsm do?

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

What are the main features of cybereason-public/owlsm?

The main features of cybereason-public/owlsm are: Networking and Security.

Which projects share features with cybereason-public/owlsm?

Projects with overlapping indexed features include: aquasecurity/tracee — Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events… bombinisecurity/bombini — eBPF Security Monitoring and Sandboxing Agent Based on Aya. cilium/cilium — Cilium is a networking, security, and observability platform for containerized environments that leverages… cilium/tetragon — Tetragon is an eBPF-based runtime security and observability toolset designed for Linux and Kubernetes environments.… gen0sec/bpfjailer — Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks… alegrey91/harpoon — 🔍 Function-level tracing tool for Seccomp profiling, with eBPF.