Hello everyone, I have a quick question. I briefly looked at the osquery code base and it looks like “exit” is not implemented yet. Also it looks like it is not implemented on
ebpfpub
. is that correct or I missed it ?
a
alessandrogario
01/17/2023, 5:59 PM
That is correct, the exit event is currently missing
There is no "exit" entry required in the serializers file, so tracing it is already possible with ebpfpub