discovered 07 Aug 2026
azazel
→ View on GitHubAzazel is a lightweight eBPF-based runtime security tracer specifically designed for malware analysis sandboxes. It operates within isolated Docker containers to capture detailed telemetry data, such as syscalls, file interactions, and network activities, producing a JSON output that allows integration with various data processing tools. Notable features include zero runtime dependencies, compile-once run-everywhere capability, and built-in heuristics for automatic alerts on suspicious behaviors.