Poolnarc
catch hidden Linux cryptominers from two eBPF hooks
Details
- External ID
- 48359911
- Source
- HN
- Company
- —
- Product
- Poolnarc
- Website domain
- github.com
- Launched
- June 1, 2026
- Cohort
- —
- Upvotes
- 5
- Upvotes percentile
- 0.12568306010928962
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Enrichment
- Theme
- low-level systems and developer tools
- Vertical
- Security
- Function
- Observability & eval
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- detect hidden linux cryptominers
- Manually corrected
- False
Could you build this?
No Detecting hidden cryptominers using eBPF kernel hooks requires kernel-level systems programming, deep Linux internals knowledge, and low-level malware analysis.
What it would actually take: The core component is written in C/Rust using `libbpf` or `aya` compiling into eBPF bytecode loaded into Linux tracepoints or kprobes (e.g., tracking Stratum mining protocol packets or thread scheduling anomalies). The hard part is avoiding false positives, minimizing CPU overhead in the kernel execution path, and defeating miner evasion techniques (process masquerading, encrypted payloads). This necessitates deep Linux kernel engineering and low-level security research expertise.
Discussion
1 comment analyzed.
Competitors
Other products that read as similar to this one — 359 launches clear the similarity bar, closest 8 shown.
Attention rank: #280 of 360 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 213 days after the earliest competitor.
- Gecit · hn · 2026-04-05 · 9 upvotes · similarity 0.50
- DropLock · hn · 2026-06-02 · 24 upvotes · similarity 0.48
- cve-2026-41940-PoC · github · 2026-09-16 · 528 upvotes · similarity 0.47
- polyxor · github · 2026-09-26 · 53 upvotes · similarity 0.47
- LLVM-jutsu: Anti-LLM obfuscation pass · hn · 2025-12-22 · 8 upvotes · similarity 0.46
- Nullsec · hn · 2026-09-17 · 6 upvotes · similarity 0.45
- Live, system-wide USB transfer sniffer in eBPF · hn · 2026-05-31 · 9 upvotes · similarity 0.45
- Spliff · hn · 2026-01-17 · 5 upvotes · similarity 0.45
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a observability & eval tool for Media & entertainment yet.