Hacker News new | ask | show | jobs
by allset_ 2391 days ago
If someone has root, it's already game over. An attacker could just hook the syscalls directly which would be more stealthy that using BPF programs.