Uploaded August 2026 | Updated September 2026, 1 hour ago
Geri Revay (Fortinet, DE)
eBPF (extended Berkeley Packet Filter) is a powerful and mysterious technology in the Linux kernel. As its name suggests, it was originally created for network‑packet filtering. However, it evolved into a more general‑purpose mechanism to observe and manipulate kernel behavior. What could go wrong?
We will not pick on eBPF because it is not a flawed or vulnerable technology, but it is a powerful one — and threat actors also recognize that. In this presentation, we will first understand how eBPF works, then look into the different use cases and how threat actors like to use them, and finally, we will look into what defenders can do to keep eBPF usage under control.
This presentation is intended for a technical audience: incident responders, malware analysts, SOC analysts, or anybody else who might face Linux malware using eBPF or be responsible for the security of Linux systems.
---
Geri Revay has more than 15 years of experience in cybersecurity. He started on this path as he specialized in network and information security in his M.Sc. in computer engineering. Since then, he has worked as a QA engineer for a security vendor, then changed to penetration testing first as an external consultant and then as an internal consultant at Siemens. He is a hacker at heart and a consultant by trade. He worked on both IT and OT systems. In the past years, he focused on security research in binary analyses and reverse engineering, which led him to Fortinet. At FortiGuard Labs, he currently does malware analysis, reverse engineering, and threat intelligence.
Geri Revay (Fortinet, DE)
eBPF (extended Berkeley Packet Filter) is a powerful and mysterious technology in the Linux kernel. As its name suggests, it was originally created for network‑packet filtering. However, it evolved into a more general‑purpose mechanism to observe and manipulate kernel behavior. What could go wrong?
We will not pick on eBPF because it is not a flawed or vulnerable technology, but it is a powerful one — and threat actors also recognize that. In this presentation, we will first understand how eBPF works, then look into the different use cases and how threat actors like to use them, and finally, we will look into what defenders can do to keep eBPF usage under control.
This presentation is intended for a technical audience: incident responders, malware analysts, SOC analysts, or anybody else who might face Linux malware using eBPF or be responsible for the security of Linux systems.
---
Geri Revay has more than 15 years of experience in cybersecurity. He started on this path as he specialized in network and information security in his M.Sc. in computer engineering. Since then, he has worked as a QA engineer for a security vendor, then changed to penetration testing first as an external consultant and then as an internal consultant at Siemens. He is a hacker at heart and a consultant by trade. He worked on both IT and OT systems. In the past years, he focused on security research in binary analyses and reverse engineering, which led him to Fortinet. At FortiGuard Labs, he currently does malware analysis, reverse engineering, and threat intelligence.



