Spliff
Correlating XDP and TLS via eBPF (Building a Linux EDR)
Details
- External ID
- 46663319
- Source
- HN
- Company
- —
- Product
- Spliff
- Website domain
- github.com
- Launched
- Jan. 17, 2026
- Cohort
- —
- Upvotes
- 5
- Upvotes percentile
- 0.09617918313570488
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Enrichment
- Theme
- systems tools and desktop utilities
- Vertical
- Security
- Function
- Observability & eval
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- linux edr via ebpf monitoring
- Manually corrected
- False
Could you build this?
No Correlating raw network packets at the XDP level with user-space TLS sessions via kernel eBPF probes requires elite Linux kernel internals, network stack, and security telemetry engineering expertise.
What it would actually take: The architecture requires an XDP driver-level eBPF program for high-speed packet ingestion, paired with kprobes/uprobes targeting OpenSSL/BoringSSL/kernel TLS socket structures to intercept plaintext data and socket file descriptors. The hard parts are tracking connection state across kernel boundaries without dropping packets, parsing complex memory offsets across varying Linux kernel/library versions (CO-RE/BTF), and correlating ephemeral cryptographic sessions with low-level sk_buff/xdp_buff representations. This demands deep expertise in Linux kernel networking, eBPF development, and low-level binary analysis.
Discussion
14 comments analyzed.
Competitors mentioned: Cilium - full CNI with XDP/Netkit for Kubernetes, Commercial EDRs - existing endpoint detection and response solutions
Concerns raised: SmartNIC hardware offload not currently usable - no CLI option, complex BPF maps not offload-compatible, Driver support varies - many NICs fall back to SKB mode instead of native XDP, Stateful flow tracking can't be fully offloaded to hardware, Requires kernel 5.x+ with BTF and XDP support
Feature requests: SmartNIC/hardware offload support with offload-compatible BPF programs, CLI option to enable XDP hardware offload mode, Process behavior tracking and anomaly detection, Event streaming integration (NATS/Kafka), Threat intelligence integration
Competitors
Other products that read as similar to this one — 1212 launches clear the similarity bar, closest 8 shown.
Attention rank: #1128 of 1213 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 78 days after the earliest competitor.
- Portview, A diagnostic-first port viewer for Linux (~930 KB, zero deps) · hn · 2026-02-08 · 5 upvotes · similarity 0.59
- esp32-poe-lldp · github · 2026-09-14 · 12 upvotes · similarity 0.58
- exl3xpu · github · 2026-09-22 · 10 upvotes · similarity 0.55
- FSM · hn · 2026-06-28 · 30 upvotes · similarity 0.55
- Live, system-wide USB transfer sniffer in eBPF · hn · 2026-05-31 · 9 upvotes · similarity 0.55
- Solo · hn · 2026-08-17 · 6 upvotes · similarity 0.54
- Extctl, a super simple systemd-sysext wrapper · hn · 2026-08-18 · 5 upvotes · similarity 0.54
- Wisp · hn · 2026-08-01 · 9 upvotes · similarity 0.54
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a observability & eval tool for Media & entertainment yet.