logo

A Deep Dive into eBPF: The Technology that Powers Tracee

ID: a0d8ccbf-a56e-5d2f-bae9-3074fa6e2621

STIX ID: report--a0d8ccbf-a56e-5d2f-bae9-3074fa6e2621

Feed Name: Aqua Security Blog

Date Published: 2020-01-06

Date Updated: 2026-04-26

...
...

This blog post introduces eBPF and Tracee, showing how to instrument the kernel to trace execve() system calls using BCC and Go bindings (kprobe/kretprobe, perf maps) with concrete code examples and a container-based demonstration; it emphasizes eBPF’s high-performance observability while noting its limitation that it can detect but not prevent malicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.