SRodi / ebpf-file-delete-tracer
View external linksLinks

This project demonstrates the use of eBPF (Extended Berkeley Packet Filter) to trace file deletion events on a Linux system. A Go userspace application loads the eBPF program from an ELF file, and attaches it to the appropriate kernel hooks to monitor file deletions.
13Oct 11, 2024Updated last year

Alternatives and similar repositories for ebpf-file-delete-tracer

Users that are interested in ebpf-file-delete-tracer are comparing it to the libraries listed below

Sorting:

Are these results useful?