Ross ROSS = Recommend OSS · open-source software intelligence for agents

qpoint-io/qtap

Qtap: An eBPF agent that captures pre-encrypted network traffic, providing rich context about egress connections and their originating processes. observed · 2026-08-28

github.com/qpoint-io/qtap · homepage · C · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

64/100

  • Activity 99
  • Release rhythm 35
  • Longevity 36

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 504
  • days_rel: n/a
  • days_push: 8
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1456 stars · 56 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Qtap is an eBPF agent that hooks TLS/SSL functions in the Linux kernel to capture network traffic before and after encryption, with full process, container, and protocol context. It provides visibility into egress traffic without proxies, certificate management, or application changes, feeding data to plugins and the QPoint platform.

Use cases

  • monitor external API calls and responses
  • capture pre-encrypted network traffic with process context
  • debug encrypted service communication
  • audit egress traffic for compliance
  • detect failed requests and errors in outbound traffic
  • discover which processes make outbound connections
  • track sensitive data leaving containers

When to choose

  • you need visibility into encrypted egress traffic without deploying proxies or sidecars
  • you want to know which processes or containers are calling external APIs and what they send
  • you run Kubernetes or Linux hosts and need out-of-band, low-overhead traffic introspection
  • you need compliance auditing of encrypted communications

When to avoid

  • you need deep packet inspection of non-TLS or kernel-bypassed traffic
  • you require a solution on non-Linux platforms
  • you cannot run eBPF due to kernel version or privilege restrictions
  • you want a fully open-source analytics stack - advanced features like alerting, RBAC, and sensitive data scanning are tied to the commercial QPoint platform

Facets

service · maturity active

monitoring tracing security logging security monitoring networking developer-tools self-hosted cloud ebpf tls-visibility egress-traffic traffic-capture observability agent network-inspection devops containers linux docker kubernetes

5 sources

Member repositories

RepositoryRoleHealth v2
qpoint-io/qtapmain64

For agents

markdown · JSON · MCP: product_card(name="qpoint-io/qtap")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem