eBPF/XDP is nice and hard to use. Packet capture is so common that I wish that there were a simpler way like pcap.
https://github.com/pythops/oryx