<https://asciinema.org/a/305585>
# ebpf
a
c
This is EXTREMELY exciting!!!!! Keep up the good work!
a
Thanks! 😄
c
Qq, have you open sourced the Osquery binary/extension that can perform this action? I would love to test this out without having to compile Osquery
Would love to compare this implementation to the standard AuditD implementation to monitor processes
a
I can build you a package if you want
this is in core (not an extension), and will eventually open source everything (the library used to generate the events is already on github)
demo package for bpf_process_events. Start with: --disable_events=false --enable_bpf_process_events=true Requires Ubuntu >= 18.10 (or kernel >= 4.18)
c
❤️