Channels
doorman
zercurity
infrastructure
code-review
queryhub
apple-silicon
carving
goquery
aws
querycon
golang
file-carving
fuzzing
help-proxy
darkbytes
process-auditing
general
windows
random
fleet-dev
tls
fim
awallaby
zentral
zeek
auditing-warroom
linen-dev
fleetosquery
plugins
jobs
arm-architecture
uptycs
android_tests
selfgroup
beyond-identity
fleet
vendor-feeds
eclecticiq-polylogyx-extension
ebpf
website
core
macos
kolide
osctrl
extensions
foundation
sql
officehours
linux
community-feeds
Powered by
#ebpf
Title
# ebpf
s
seph
04/25/2018, 7:02 PM
https://github.com/capsule8/capsule8/blob/master/docs/KProbes.md
looks like the simple intro. It's based on kprobes. Additionally leverages cgroups so you can instrument differently at different processes.
m
maestretti
04/25/2018, 11:14 PM
As I recall it uses standard perf techniques instead of ebpf so broader kernel support but not as performant (more context switches etc).
s
seph
04/25/2018, 11:22 PM
Uses kprobes. My coworkers think it's performant.
b
b0l
04/30/2018, 7:03 PM
yes, it uses kprobes and perf_event_open to get data from kernel ring buffer.
7 Views