Behavioral hidden-cryptominer detector for Linux in eBPF — flags processes talking to mining-pool ports while spoofing kernel-thread names. No signatures, no agent, no cloud. CO-RE portable. - yeet...
Behavioral detector for hidden cryptominers on Linux. Runs a scan, prints a verdict no signature DB, no agent, no cloud. poolnarc watches every outbound TCP connection at the kernel boundary with eB…