Uploaded September 2025 | Updated September 2026, 2 weeks ago
eCapture.cc allows you to capture SSL/TLS in plaintext without needing a CA certificate. It uses eBPF and it requires Linux/Android kernel on either amd64 or arm64.
Marcos Nils shows us how to use it to debug all TLS requests from Docker to any container image repository.
eCapture also supports:
- openssi, libressl, boringssl, gnutls, gotls & nspr(nss)
- capturing bash & zsh commands for Host Security Audit.
- sql queries from mysald 5.6 & postgres 10
- pcap mode
There is more to this:
- Sign-up at πΊ makeitwork.tv for the full length content
- Tune into π§ https://makeitwork.fm for the podcast
- Join πͺ© makeitwork.club for regular members-only discussions
eCapture.cc allows you to capture SSL/TLS in plaintext without needing a CA certificate. It uses eBPF and it requires Linux/Android kernel on either amd64 or arm64.
Marcos Nils shows us how to use it to debug all TLS requests from Docker to any container image repository.
eCapture also supports:
- openssi, libressl, boringssl, gnutls, gotls & nspr(nss)
- capturing bash & zsh commands for Host Security Audit.
- sql queries from mysald 5.6 & postgres 10
- pcap mode
There is more to this:
- Sign-up at πΊ makeitwork.tv for the full length content
- Tune into π§ https://makeitwork.fm for the podcast
- Join πͺ© makeitwork.club for regular members-only discussions










