Threat From The Inside: Investigate eBPF Malware @FIRSTdotorg
Threat From The Inside: Investigate eBPF Malware  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 1 hour ago
Geri Revay (Fortinet, DE)

eBPF (extended Berkeley Packet Filter) is a powerful and mysterious technology in the Linux kernel. As its name suggests, it was originally created for network‑packet filtering. However, it evolved into a more general‑purpose mechanism to observe and manipulate kernel behavior. What could go wrong?

We will not pick on eBPF because it is not a flawed or vulnerable technology, but it is a powerful one — and threat actors also recognize that. In this presentation, we will first understand how eBPF works, then look into the different use cases and how threat actors like to use them, and finally, we will look into what defenders can do to keep eBPF usage under control.

This presentation is intended for a technical audience: incident responders, malware analysts, SOC analysts, or anybody else who might face Linux malware using eBPF or be responsible for the security of Linux systems.

---

Geri Revay has more than 15 years of experience in cybersecurity. He started on this path as he specialized in network and information security in his M.Sc. in computer engineering. Since then, he has worked as a QA engineer for a security vendor, then changed to penetration testing first as an external consultant and then as an internal consultant at Siemens. He is a hacker at heart and a consultant by trade. He worked on both IT and OT systems. In the past years, he focused on security research in binary analyses and reverse engineering, which led him to Fortinet. At FortiGuard Labs, he currently does malware analysis, reverse engineering, and threat intelligence.
Threat From The Inside: Investigate eBPF MalwareThree Musketeers: CVE, CSAF, and VEXMaximizing the Potential of AWS-WAFHack Your Boards Mindset: Closing the Strategy-Operations Gap via Board Game SimulationsPanel: CVE Record Disputes Discussion: Policy, Process, and Opportunities for Improvement
FIRST |

Threat From The Inside: Investigate eBPF Malware

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER