|
|
|
|
|
by tarasglek
515 days ago
|
|
It is not clear what the architecture for system-call capture is. Is it ptrace, ebpf or some custom thing or some combo? What is the overhead of running this? The tool looks really cool, hopefully it moves ui state of art beyond windows xperf |
|
[1]https://github.com/falcosecurity/libs/