discovered 03 Aug 2026
nysm
→ View on GitHubnysm is an eBPF stealth container designed to facilitate the post-exploitation of systems by making offensive tools undetectable to system administration utilities. It achieves this by obscuring new eBPF programs, audit logs, PIDs, and sockets from tools like bpftool, ps, and auditd. Key features include the ability to run commands in a hidden context, with options for background execution and self-destruction after use.