{"adoption": {"forks": 304, "observed_at": "2026-08-28T04:08:09.586943+00:00", "stars": 3553}, "canonical_url": "https://ross.abutalabs.com/products/ebpf-for-windows", "card": {"archived": false, "artifact_type": "framework", "description": "eBPF implementation that runs on top of Windows", "domain": ["operating-systems", "security", "networking", "developer-tools"], "enriched": true, "function": ["security", "networking", "tracing", "monitoring", "developer-tools"], "health_score": 100, "homepage": null, "language": "C", "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["microsoft/ebpf-for-windows"], "name": "microsoft/ebpf-for-windows", "platform": ["windows"], "pushed_at": "2026-08-26T22:48:49+00:00", "repo": "microsoft/ebpf-for-windows", "stars": 3553, "tags": ["ebpf", "bpf", "kernel-programmability", "jit-compiler", "verifier", "windows-kernel", "observability", "packet-filtering", "ddos-protection", "xdp", "driver-development", "native-code-generation"], "topics": [], "urls": [], "use_cases": ["run eBPF programs on Windows", "port Linux eBPF tools and programs to Windows", "packet filtering and network processing on Windows servers", "mitigate DDoS attacks at the kernel level on Windows", "observe and trace kernel and network events on Windows", "verify eBPF bytecode before loading it into the Windows kernel", "compile eBPF programs into signed Windows drivers"], "what_it_is": "eBPF for Windows is an MIT-licensed implementation of the eBPF runtime that runs on top of the Windows kernel, letting developers reuse familiar Linux eBPF toolchains (clang, ELF bytecode, verifier APIs). It verifies and loads eBPF programs either as natively generated Windows driver modules or via a uBPF JIT service, enabling kernel programmability for networking, DoS protection, and observability.", "when_to_avoid": ["You are targeting Linux or macOS, where the kernel's native eBPF stack is the right choice", "You require full feature parity with Linux eBPF, since this project is a work-in-progress with evolving hook and API coverage", "You need a guaranteed production-hardened eBPF stack today rather than an actively maturing one", "You only need user-space sandboxing or tracing without kernel integration"], "when_to_choose": ["You need eBPF-based observability, tracing, or packet processing on Windows rather than Linux", "You want to reuse existing eBPF toolchains, bytecode, and APIs from the Linux ecosystem on Windows", "You need verified, safe kernel extensibility on Windows, especially with HVCI enforced (prefer the native driver mode)", "You are building Windows networking or security tooling that benefits from programmable kernel hooks"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/ebpf-for-windows", "repo": "microsoft/ebpf-for-windows", "role": "main", "score": 86}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:08:09.586943+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T18:34:18.734691+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc4f31a32aaa88bf8c4415abc4c156e8efb2be3da656d6a5cdf491c1fc2984dc", "fetched_at": "2026-08-28T04:08:09.586943+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/ebpf-for-windows"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 99, "longevity": 100, "rhythm": 60}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["prerelease_only"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1974, "days_push": 7, "days_rel": 14, "gap_med": 35.0, "n_releases_24m": 11}, "score": 86, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}