GNU/Linux ◆ xterm-256color ◆ zsh 366 views

The bpf_process_events table is able to capture calls to the execve() system call using tracepoints.

Implemented using the ebpfpub library (https://github.com/trailofbits/ebpfpub).