Using LSM Hooks with Tracee to Overcome Gaps with Syscall Tracing
ID: a297a657-915a-555d-b79f-ad63e208b6b5
STIX ID: report--a297a657-915a-555d-b79f-ad63e208b6b5
Feed Name: Aqua Security Blog
Tracee is an open-source Linux runtime security and forensics tool that leverages eBPF programs attached to LSM hooks to capture kernel-resolved pathnames and events, addressing issues such as ambiguous relative paths, symbolic links, TOCTOU race conditions, and the complexity of tracking file descriptors; the post illustrates these problems with examples, lists the LSM hooks Tracee supports, and recommends using LSM hooks alongside syscall tracing for more accurate runtime security telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
