Similar tools already available in many distros:
https://github.com/bpftrace/bpftrace/blob/master/tools/sslsn...
https://github.com/iovisor/bcc/blob/master/tools/sslsniff.py
https://embracethered.com/blog/posts/2021/offensive-bpf-snif...
On Ubuntu for example I can just "sudo apt install bpfcc-tools", then run "sudo sslsniff-bpfcc" and see curl TLS traffic right away.