@clong Thanks for the article. It is really helpful. As you told that only three different syscall, can you tell me which three syscall it is able to monitor?
@clong I know that go-audit will do better job in terms of syscall monitoring, but I just wanted to know whether it is possible using osquery to monitor syscall like auditd or go-audit does?