A Deep Dive into eBPF: The Technology that Powers Tracee
ID: a0d8ccbf-a56e-5d2f-bae9-3074fa6e2621
STIX ID: report--a0d8ccbf-a56e-5d2f-bae9-3074fa6e2621
Feed Name: Aqua Security Blog
This blog post introduces eBPF and Tracee, showing how to instrument the kernel to trace execve() system calls using BCC and Go bindings (kprobe/kretprobe, perf maps) with concrete code examples and a container-based demonstration; it emphasizes eBPF’s high-performance observability while noting its limitation that it can detect but not prevent malicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
