microsoft / microsoft/ebpf-for-windows
Long term development plan & goals
- Dominant language
- C
- Stars
- 3.6k
- Forks
- 311
- Avg merge
- 6d 10h
- Merged PRs (30d)
- 21
Description
It's not clear from the existing documentation what the longer term goals and plans for this project are.
I am interested in using and contributing as a representative of a security software vendor.
I have seen the the file system filter integration proposal. Is this the direction of the project - to take take existing kernel integration points (WPF, minifilter, Ob process and thread callback, registry callbacks) and expose them through eBP?
Or are there plans to expose lower level functional - ala kprobes - for example by making hook points at the syscall SSDT layer. That would be a very powerful and useful mechanism.
Contributor guide
Research direction
The issue names no file, test, or entry point. Start by reviewing the existing documentation and the referenced file system filter integration proposal; done would be a documented, agreed long-term roadmap covering the proposed kernel integration points and possible lower-level hooks.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, operating-systems, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100