yeet-src/usbsnoop
Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no hardware sniffer. CO-RE portable.
GitHub repository with 62 stars and 4 forks.
Language: JavaScript
Topics: bpf, co-re, ebpf, libbpf, linux, observability, reverse-engineering, tracing, usb, usb-sniffer