Enforcing Security Policy at the Kernel’s Decision Points: eBPF LSM Hooks (opens in new tab)
Every time a process opens a file, spawns a child, or connects to a socket, the Linux kernel reaches an internal checkpoint.
Read the original articleEvery time a process opens a file, spawns a child, or connects to a socket, the Linux kernel reaches an internal checkpoint.
Read the original article