You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi!
I think, it would be nice to support some selectors that we have for kprobes/tracepoints/lsm hooks. According to this uprobe policies are only support matchPid selector:
returnfmt.Errorf("Only matchPIDs selector is supported")
With this uprobe support we can do a lot of interesting things. For example, we can monitor for suspicious commands user executes from shell. More details can be found in nice Quarkslab blog post.
Describe your proposed solution
No response
Code of Conduct
I agree to follow this project's Code of Conduct
The text was updated successfully, but these errors were encountered:
Is there an existing issue for this?
Is your feature request related to a problem?
No response
Describe the feature you would like
Hi!
I think, it would be nice to support some selectors that we have for kprobes/tracepoints/lsm hooks. According to this uprobe policies are only support
matchPid
selector:tetragon/pkg/sensors/tracing/genericuprobe.go
Lines 226 to 235 in 21cb4fd
With this uprobe support we can do a lot of interesting things. For example, we can monitor for suspicious commands user executes from shell. More details can be found in nice Quarkslab blog post.
Describe your proposed solution
No response
Code of Conduct
The text was updated successfully, but these errors were encountered: