Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection
ID: 6093d7ef-d79f-59cc-bc3f-c4de46e41b22
STIX ID: report--6093d7ef-d79f-59cc-bc3f-c4de46e41b22
Feed Name: GBHackers
Furtex is a publicly released Linux toolkit (MIT-licensed) containing over 100 tools that abuse io_uring, eBPF/BPF maps, and raw syscalls to enable asynchronous I/O, EDR/Runtime sensor evasion (including Falco), BPF reconnaissance and manipulation, process injection, raw packet operations, and alternate data-exfiltration paths. The project highlights that telemetry relying solely on syscall entry tracepoints or process-name rules can be bypassed, and it advises defenders to monitor io_uring-originated activity, suspicious BPF interactions, and privileged capability usage (e.g., CAP_BPF, CAP_NET_ADMIN) on modern kernels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
