Linux did implement an API for safely instrumenting these types of events, eBPF.
Many EDR and other security products are beginning to use it, although IIRC Crowdstrike does not yet.
Many EDR and other security products are beginning to use it, although IIRC Crowdstrike does not yet.
No comments yet.