Hey @mtremsal! We are using kprobes to map processes inside containers. Basic fd tracking for socket_events is being implemented, and will be useful for implementing FIM too
m
mtremsal
02/26/2019, 3:41 PM
Hi Alessandro. I work at Datadog. Since we already have an agent that handles live process and container monitoring, I'm looking more specifically at FIM at moment. I'll keep an eye on your PRs; really interesting stuff. 👍
😌 1
a
alessandrogario
02/26/2019, 3:42 PM
Thanks! We'll make sure to post updates about it here on Slack! 🙂