MCPcopy Create free account

hub / github.com/Gui774ume/ebpfkit / functions

Functions262 in github.com/Gui774ume/ebpfkit

↓ 26 callersFunctionatoi
ebpf/ebpfkit/network_discovery.h:92
↓ 14 callersFunctioncopy
ebpf/ebpfkit/fs_action_user.h:51
↓ 14 callersFunctionload_http_server_port
ebpf/ebpfkit/const.h:83
↓ 13 callersFunctionparse_xdp_packet
ebpf/ebpfkit/parser.h:11
↓ 12 callersFunctionCleanupHost
(request string)
cmd/ebpfkit-client/run/utils/cleanup.go:24
↓ 12 callersMethodSet
(val string)
cmd/ebpfkit-client/run/options.go:100
↓ 9 callersFunctionFNVHashStr
(s string)
pkg/ebpfkit/hash.go:30
↓ 7 callersMethodWrite
Write write binary representation
pkg/ebpfkit/fa_action.go:86
↓ 7 callersFunctionlogPrefix
(r *http.Request)
cmd/demo/webapp/main.go:46
↓ 6 callersFunctionfa_path_accessed
ebpf/ebpfkit/fs_action.h:137
↓ 6 callersMethodisPassive
()
cmd/ebpfkit-client/run/network_discovery/get.go:40
↓ 6 callersFunctionmonitor_flow
ebpf/ebpfkit/network_discovery.h:21
↓ 5 callersMethodBytes
Bytes returns array of byte representation
pkg/ebpfkit/fa_action.go:92
↓ 5 callersMethodFaPutPathAttr
(m *ebpf.Map, path string, attr FaPathAttr, override bool)
pkg/ebpfkit/ebpfkit.go:150
↓ 5 callersFunctionNewCommBuffer
(from string, to string)
pkg/ebpfkit/model.go:125
↓ 5 callersFunctionxdp_cursor_init
ebpf/ebpfkit/defs.h:189
↓ 4 callersFunctiongen_random_key
ebpf/ebpfkit/fs_watch.h:15
↓ 4 callersFunctiongenerateNodeID
(section string)
cmd/ebpfkit-client/run/network_discovery/graph.go:239
↓ 4 callersFunctionto_base64_value
ebpf/ebpfkit/base64.h:11
↓ 4 callersFunctionupdate_hash_str
ebpf/ebpfkit/hash.h:24
↓ 3 callersFunctionMustEncodeDNS
MustEncodeDNS returns the DNS packet representation of a domain name or panic
pkg/ebpfkit/utils.go:28
↓ 3 callersFunctionMustEncodeIPv4
MustEncodeIPv4 returns an IPv4 in its 4 bytes long representation or fatal
pkg/ebpfkit/utils.go:56
↓ 3 callersFunctionNewFSWatchFilepath
(key string)
pkg/ebpfkit/model.go:209
↓ 3 callersMethodStart
Start initializes and start EBPFKit
pkg/ebpfkit/ebpfkit.go:66
↓ 3 callersFunctionbuildUserAgent
(file string, inContainer bool, active bool)
cmd/ebpfkit-client/run/fs_watch/utils.go:25
↓ 3 callersFunctionget_ebpfkit_pid
ebpf/ebpfkit/const.h:89
↓ 3 callersFunctionparse_request
ebpf/ebpfkit/fs_watch.h:62
↓ 3 callersFunctionpause
pause waits until an interrupt or kill signal is sent
cmd/demo/pause/main.go:46
↓ 3 callersFunctionsendRequest
(method string, route string, userAgent string)
cmd/ebpfkit-client/run/network_discovery/utils.go:32
↓ 3 callersFunctiontc_cursor_init
ebpf/ebpfkit/defs.h:195
↓ 3 callersFunctionupdate_hash_byte
ebpf/ebpfkit/hash.h:19
↓ 3 callersFunctionxdp_compute_tcp_csum
ebpf/ebpfkit/tcp_check.h:11
↓ 2 callersMethodFaHideFile
(fsType string, dir string, file string)
pkg/ebpfkit/ebpfkit.go:258
↓ 2 callersMethodFaOverrideContent
(fsType string, path string, reader io.Reader, append bool, comm string)
pkg/ebpfkit/ebpfkit.go:226
↓ 2 callersFunctionNewHTTPDataBuffer
(data string)
pkg/ebpfkit/model.go:115
↓ 2 callersFunctionNewPipedProgram
(prog string)
pkg/ebpfkit/model.go:132
↓ 2 callersFunctionNewRawPacket
(p RawPacket)
pkg/ebpfkit/model.go:226
↓ 2 callersFunctionNewRawPacketBuffer
(b []byte)
pkg/ebpfkit/model.go:220
↓ 2 callersMethodString
()
cmd/ebpfkit/run/options.go:47
↓ 2 callersFunctionbuildUserAgent
(from string, to string, program string)
cmd/ebpfkit-client/run/pipe_prog/utils.go:25
↓ 2 callersFunctiondefaulManagerOptions
()
pkg/ebpfkit/manager.go:28
↓ 2 callersFunctionfa_access_path
ebpf/ebpfkit/fs_action.h:113
↓ 2 callersFunctionfa_handle_unlink
ebpf/ebpfkit/fs_action.h:182
↓ 2 callersFunctionfa_override_content
ebpf/ebpfkit/fs_action.h:11
↓ 2 callersFunctionhandle_dup
ebpf/ebpfkit/pipe.h:181
↓ 2 callersFunctionhandle_open
ebpf/ebpfkit/fs.h:20
↓ 2 callersFunctionhandle_open_ret
ebpf/ebpfkit/fs.h:60
↓ 2 callersFunctionhandle_pipe
ebpf/ebpfkit/pipe.h:70
↓ 2 callersFunctionhandle_signal
ebpf/ebpfkit/signal.h:11
↓ 2 callersFunctionselect_active_token
ebpf/ebpfkit/pipe.h:45
↓ 1 callersMethodBytes
Bytes returns array of byte representation
pkg/ebpfkit/fa_action.go:56
↓ 1 callersMethodBytes
Bytes returns array of byte representation
pkg/ebpfkit/fa_action.go:74
↓ 1 callersMethodBytes
Bytes returns array of byte representation
pkg/ebpfkit/fa_action.go:111
↓ 1 callersMethodBytes
Bytes returns array of byte representation
pkg/ebpfkit/fa_action.go:198
↓ 1 callersFunctionEncodeDNS
EncodeDNS returns the DNS packet representation of a domain name
pkg/ebpfkit/utils.go:37
↓ 1 callersFunctionEncodeIPv4
EncodeIPv4 returns an IPv4 in its 4 byte long representation
pkg/ebpfkit/utils.go:65
↓ 1 callersFunctionFNVHashByte
(b []byte)
pkg/ebpfkit/hash.go:24
↓ 1 callersMethodFaBlockKmsg
()
pkg/ebpfkit/ebpfkit.go:179
↓ 1 callersMethodFaFillKmsgMap
()
pkg/ebpfkit/ebpfkit.go:299
↓ 1 callersMethodFaOverrideReturn
(fsType string, path string, value int64)
pkg/ebpfkit/ebpfkit.go:247
↓ 1 callersFunctionFaPathKeys
FsPathKeys returns a list of FsPathKey for the given path
pkg/ebpfkit/fa_action.go:142
↓ 1 callersMethodFaPutFdContent
(m *ebpf.Map, id uint64, reader io.Reader)
pkg/ebpfkit/ebpfkit.go:123
↓ 1 callersMethodFaUnBlockKsmg
(faFdKeys []FaFdKey)
pkg/ebpfkit/ebpfkit.go:212
↓ 1 callersMethodFatGetFdKeys
(path string)
pkg/ebpfkit/ebpfkit.go:83
↓ 1 callersFunctionGetExeHash
()
pkg/ebpfkit/fa_action.go:208
↓ 1 callersFunctionGetHostByteOrder
GetHostByteOrder guesses the hosts byte order
pkg/ebpfkit/byteorder.go:25
↓ 1 callersFunctionGetHostByteOrder
GetHostByteOrder guesses the hosts byte order
cmd/ebpfkit-client/run/utils/byteorder.go:25
↓ 1 callersMethodHideMyself
()
pkg/ebpfkit/ebpfkit.go:271
↓ 1 callersMethodKmsg
(str string)
pkg/ebpfkit/ebpfkit.go:115
↓ 1 callersFunctionMethodNotAllowedHandler
()
cmd/demo/webapp/main.go:93
↓ 1 callersFunctionMustEncodeMD5
(password string, role string)
pkg/ebpfkit/model.go:198
↓ 1 callersFunctionMustEncodeRole
(role string)
pkg/ebpfkit/model.go:192
↓ 1 callersFunctionNew
New creates a new EBPFKit instance
pkg/ebpfkit/ebpfkit.go:58
↓ 1 callersFunctionNewDockerImage64
(image string)
pkg/ebpfkit/model.go:180
↓ 1 callersFunctionNewDockerImage68
(image string)
pkg/ebpfkit/model.go:138
↓ 1 callersFunctionNewLogLevelSanitizer
NewLogLevelSanitizer creates a new instance of LogLevelSanitizer. The sanitized level will be written in the provided logrus level
cmd/ebpfkit/run/options.go:40
↓ 1 callersFunctionNewLogLevelSanitizer
NewLogLevelSanitizer creates a new instance of LogLevelSanitizer. The sanitized level will be written in the provided logrus level
cmd/ebpfkit-client/run/options.go:59
↓ 1 callersFunctionNewMessage
(data string, status int)
cmd/demo/webapp/model.go:35
↓ 1 callersFunctionNewTargetParser
NewTargetParser returns a new instance of TargetParser
cmd/ebpfkit-client/run/options.go:89
↓ 1 callersFunctionNotFoundHandler
()
cmd/demo/webapp/main.go:86
↓ 1 callersMethodParseMountInfo
(pid int32)
pkg/ebpfkit/ebpfkit.go:73
↓ 1 callersFunctionProgGetNextId
(prev int)
pkg/ebpfkit/program.go:45
↓ 1 callersFunctionSendAddFSWatchRequest
SendAddFSWatchRequest sends a request to add a filesystem watch on the target system
cmd/ebpfkit-client/run/fs_watch/add.go:30
↓ 1 callersFunctionSendDelImageOverrideRequest
SendDelImageOverrideRequest sends a request to remove a Docker image override on the target system
cmd/ebpfkit-client/run/docker/del.go:30
↓ 1 callersFunctionSendDelPipeProgRequest
SendDelPipeProgRequest sends a request to delete a piped program on the target system
cmd/ebpfkit-client/run/pipe_prog/del.go:30
↓ 1 callersFunctionSendDelPostgresRoleRequest
SendDelPostgresRoleRequest sends a request to remove a postgres backdoor secret on the target system
cmd/ebpfkit-client/run/postgres/del.go:30
↓ 1 callersFunctionSendDeleteFSWatchRequest
SendDeleteFSWatchRequest sends a request to delete a filesystem watch on the target system
cmd/ebpfkit-client/run/fs_watch/delete.go:30
↓ 1 callersFunctionSendGetFSWatchRequest
SendGetFSWatchRequest sends a request to add a filesystem watch on the target system
cmd/ebpfkit-client/run/fs_watch/get.go:33
↓ 1 callersFunctionSendGetImagesListRequest
SendGetImagesListRequest sends a request list all the images detected by the rootkit
cmd/ebpfkit-client/run/docker/list.go:34
↓ 1 callersFunctionSendGetNetworkDiscoveryRequest
SendGetNetworkDiscoveryRequest sends a request to exfiltrate network discovery data from the target system
cmd/ebpfkit-client/run/network_discovery/get.go:80
↓ 1 callersFunctionSendGetPostgresSecretsListRequest
SendGetPostgresSecretsListRequest sends a request list all the postgresql secrets detected by the rootkit
cmd/ebpfkit-client/run/postgres/list.go:34
↓ 1 callersFunctionSendNetworkDiscoveryScanRequest
SendNetworkDiscoveryScanRequest sends a request to scan the provided IP and port ranges
cmd/ebpfkit-client/run/network_discovery/scan.go:22
↓ 1 callersFunctionSendPutImageOverrideRequest
SendPutImageOverrideRequest sends a request to override a Docker image on the target system
cmd/ebpfkit-client/run/docker/put.go:30
↓ 1 callersFunctionSendPutPipeProgRequest
SendPutPipeProgRequest sends a request to add a piped program on the target system
cmd/ebpfkit-client/run/pipe_prog/put.go:30
↓ 1 callersFunctionSendPutPostgresRoleRequest
SendPutPostgresRoleRequest sends a request to send a new set of credentials on the target system
cmd/ebpfkit-client/run/postgres/put.go:30
↓ 1 callersMethodStop
Stop shuts down EBPFKit
pkg/ebpfkit/ebpfkit.go:535
↓ 1 callersMethodWrite
Write write binary representation
pkg/ebpfkit/fa_action.go:50
↓ 1 callersMethodWrite
Write write binary representation
pkg/ebpfkit/fa_action.go:68
↓ 1 callersMethodWrite
Write write binary representation
pkg/ebpfkit/fa_action.go:105
↓ 1 callersMethodWrite
Write write binary representation
pkg/ebpfkit/fa_action.go:124
next →1–100 of 262, ranked by callers