While we take great pride in the tools we develop, we also benefit from tools maintained outside of the company. In 2022, we had more than 400 pull requests merged into non-ToB repos. We thank the maintainers for innumerable hours spent on this work! https://t.co/sewVcs1Xsx
My last BPF article has a new home!
In case you missed it, it's a handy introduction on programmatically generating tracers at runtime using the LLVM libraries. Be sure to check out the companion code too: https://t.co/Ft5bBN0ckb
https://t.co/A51FPwQsBR
Ever wanted to dynamically codegen and load your #bpf programs from C++ with nothing except #llvm?
Take a look at this example we have released!
https://t.co/ROzv0I526l
Inspired by the Linux version of #ProcMon, I wrote a new SocketMonitor example for the ebpfpub library from @trailofbits! You can find it here: https://t.co/XxJIIBvjYS
Syscall fault injection is a really cool testing technique, but doing it reliably is hard. BPF has got your back, thanks to the bpf_override_return() helper! Here's a small tool I developed to play with it: https://t.co/KL7LFlujM3
BPF provides powerful system tracing capability on Linux but it is difficult to integrate into your applications. Today I'm releasing a BPF library, ebpf-common, and a tracing library based on LLVM: https://t.co/XxJIIBvjYS
Tired, but excited about all the awesome interactions @QueryConf this year. Thanks to @trailofbits, @Kolideco and @CarbonBlack_Inc, well done.
Biggest takeaway this year is that the @osquery community deeply cares about the privacy of users.
@trailofbits generously supports the infosec community in many ways (https://t.co/mAIne2rUgp, hosting @QueryConf, etc) 🙌
We're stoked they've joined our "Friends of Objective-See" program & as an OBTS conference sponsor 🥳
Mahalo for your community commitment & involvement !😍
We are happy to announce the first two talks for @QueryConf, with many more on the way. First up, Stefano Bonicatti of @trailofbits will share our work and vision for osql, our fork of osquery https://t.co/gAFupC5nDr
Second, our own @alessandrogario will review the past and present state of Linux event monitoring with osquery, including a demonstration of our new eBPF backend.
Based on popular demand, we have added Press Passes to @QueryConf! Please register via eventbrite for a free ticket to attend the conference. https://t.co/JsNPdMOcAm