Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Spliff

Correlating XDP and TLS via eBPF (Building a Linux EDR)

Details

External ID
46663319
Source
HN
Company
—
Product
Spliff
Website domain
github.com
Launched
Jan. 17, 2026
Cohort
—
Upvotes
5
Upvotes percentile
0.09617918313570488
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Enrichment

Theme
systems tools and desktop utilities
Vertical
Security
Function
Observability & eval
Audience
Developer
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
linux edr via ebpf monitoring
Manually corrected
False

Could you build this?

No Correlating raw network packets at the XDP level with user-space TLS sessions via kernel eBPF probes requires elite Linux kernel internals, network stack, and security telemetry engineering expertise.

What it would actually take: The architecture requires an XDP driver-level eBPF program for high-speed packet ingestion, paired with kprobes/uprobes targeting OpenSSL/BoringSSL/kernel TLS socket structures to intercept plaintext data and socket file descriptors. The hard parts are tracking connection state across kernel boundaries without dropping packets, parsing complex memory offsets across varying Linux kernel/library versions (CO-RE/BTF), and correlating ephemeral cryptographic sessions with low-level sk_buff/xdp_buff representations. This demands deep expertise in Linux kernel networking, eBPF development, and low-level binary analysis.

Discussion

14 comments analyzed.

Competitors mentioned: Cilium - full CNI with XDP/Netkit for Kubernetes, Commercial EDRs - existing endpoint detection and response solutions

Concerns raised: SmartNIC hardware offload not currently usable - no CLI option, complex BPF maps not offload-compatible, Driver support varies - many NICs fall back to SKB mode instead of native XDP, Stateful flow tracking can't be fully offloaded to hardware, Requires kernel 5.x+ with BTF and XDP support

Feature requests: SmartNIC/hardware offload support with offload-compatible BPF programs, CLI option to enable XDP hardware offload mode, Process behavior tracking and anomaly detection, Event streaming integration (NATS/Kafka), Threat intelligence integration

Competitors

Other products that read as similar to this one — 1212 launches clear the similarity bar, closest 8 shown.

Attention rank: #1128 of 1213 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 78 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a observability & eval tool for Media & entertainment yet.