Hacker News new | ask | show | jobs
by aeadio 662 days ago
Linux did implement an API for safely instrumenting these types of events, eBPF.

Many EDR and other security products are beginning to use it, although IIRC Crowdstrike does not yet.