What is eCapture? @gerhardlazu
What is eCapture?  @gerhardlazu
Uploaded September 2025 | Updated September 2026, 2 weeks ago
eCapture.cc allows you to capture SSL/TLS in plaintext without needing a CA certificate. It uses eBPF and it requires Linux/Android kernel on either amd64 or arm64.

Marcos Nils shows us how to use it to debug all TLS requests from Docker to any container image repository.

eCapture also supports:
- openssi, libressl, boringssl, gnutls, gotls & nspr(nss)
- capturing bash & zsh commands for Host Security Audit.
- sql queries from mysald 5.6 & postgres 10
- pcap mode

There is more to this:
- Sign-up at πŸ“Ί makeitwork.tv for the full length content
- Tune into 🎧 https://makeitwork.fm for the podcast
- Join πŸͺ© makeitwork.club for regular members-only discussions
What is eCapture?First impressions: Parca Agent on K8s v1.28 running via Talos v1.5We made our ghcr.io 2x faster with AWS CloudFrontLearning from Matts homelab: Incus, Ansible and NO Kubernetes.eCapture.cc SSL/TLS in plaintext #ebpf #ssl #tlsHunting double slashes #elixir #varnish #cdnLets build a CDN - Part 2starship explainTrust me, the docs are good and up-to-dateSupercharge your development workflow with these CLI toolsThe OG BikeshedThe Square Hole - KubeCon EU 2024 proposed talk - Ken Cochrane & Gerhard Lazu
Gerhard Lazu |

What is eCapture?

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER