logo

Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection

ID: 6093d7ef-d79f-59cc-bc3f-c4de46e41b22

STIX ID: report--6093d7ef-d79f-59cc-bc3f-c4de46e41b22

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Divya

...
...

Furtex is a publicly released Linux toolkit (MIT-licensed) containing over 100 tools that abuse io_uring, eBPF/BPF maps, and raw syscalls to enable asynchronous I/O, EDR/Runtime sensor evasion (including Falco), BPF reconnaissance and manipulation, process injection, raw packet operations, and alternate data-exfiltration paths. The project highlights that telemetry relying solely on syscall entry tracepoints or process-name rules can be bypassed, and it advises defenders to monitor io_uring-originated activity, suspicious BPF interactions, and privileged capability usage (e.g., CAP_BPF, CAP_NET_ADMIN) on modern kernels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.