Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Furtex: Advanced Linux Toolkit for Security Experts

Furtex: Advanced Linux Toolkit for Security Experts

Posted on July 21, 2026 By CWS

A newly introduced open-source project, Furtex, is making waves among security researchers and red team operators. This Linux-centric toolkit is designed to facilitate post-exploitation and evasion research exclusively for authorized users.

Understanding Furtex’s Unique Offerings

Furtex distinguishes itself by incorporating raw io_uring system calls along with BPF and eBPF tools. It aims to enable EDR-evasion research without the dependency on liburing or larger frameworks. This suite of single-focused tools is crafted to explore the effectiveness of modern Linux telemetry, kernel monitoring, and endpoint defense mechanisms.

The developers of Furtex have clearly stated that the toolkit is meant solely for authorized research, penetration testing, CTF scenarios, and defensive development purposes.

Breaking Down Furtex’s Core Components

Furtex is organized into five primary sections: io_uring, bpf, ebpf, edrs, and techniques. The io_uring segment features 13 tools that leverage raw kernel interfaces for various operations, including file and network I/O, process injection, and data transfers.

The project’s research focus is on the visibility gap that arises when tasks are executed via io_uring work queues rather than conventional syscall-dispatch paths. This is critical because many security solutions rely on syscall tracing and kprobes to gather Linux telemetry.

Advanced Capabilities and Security Considerations

Furtex expands its scope with BPF and eBPF functionalities, offering utilities for examining loaded BPF maps, links, and Linux Security Module hooks. It also provides eBPF prototypes for monitoring processes, networks, and terminal activities. A significant portion of the toolkit is dedicated to EDR reconnaissance and evasion, with around 75 utilities categorized by privilege needs.

Developed by MatheuZSecurity and hosted on GitHub, Furtex includes a techniques directory aimed at enhancing Falco detection engineering by testing bypass conditions against default rulesets. This allows defenders to identify potential over-reliance on single event sources.

Essential Tools and Future Implications

Furtex requires several dependencies such as GCC, Clang, Make, and Linux kernel headers. Some eBPF features demand kernel BTF support, spanning Linux kernel versions 5.4 to 5.19. While Furtex is beneficial for evaluating Linux EDR coverage, its dual-use nature necessitates careful handling.

Security teams are advised to utilize Furtex for threat modeling, monitoring io_uring activities, and tracking BPF modifications, ensuring that audit configurations are safeguarded. By doing so, they can correlate kernel events with process and network telemetry, ultimately strengthening their security operations.

Cyber Security News Tags:BPF, CTF environments, cybersecurity tools, eBPF, EDR evasion, endpoint monitoring, Evasion, Furtex, io_uring, Linux security, penetration testing, post-exploitation, Red Team, security researchers

Post navigation

Previous Post: Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
Next Post: Cyberattack Turns Telegram Bots Into Covert Control System

Related Posts

Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data Cyber Security News
JetBrains Security Flaws Risk Code Execution and Account Breach JetBrains Security Flaws Risk Code Execution and Account Breach Cyber Security News
Kubernetes Misconfigurations Enable Dangerous Cloud Exploits Kubernetes Misconfigurations Enable Dangerous Cloud Exploits Cyber Security News
ClipXDaemon: A New C2-Less Threat to Linux Cryptocurrency Users ClipXDaemon: A New C2-Less Threat to Linux Cryptocurrency Users Cyber Security News
DrayOS Routers Vulnerability Let Attackers Execute Malicious Code Remotely DrayOS Routers Vulnerability Let Attackers Execute Malicious Code Remotely Cyber Security News
LiteLLM Attack Risks 2,500 Companies and 434,000 Pipelines LiteLLM Attack Risks 2,500 Companies and 434,000 Pipelines Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark