tracee
tracee copied to clipboard
[FEAT] add new bpf_attach event
Prerequisites
- [ ] This issue is an EPIC issue (add label: EPIC).
- [ ] This issue is an EPIC TASK (add issue to EPIC description).
Select one OR another:
- [x] I'll create a PR to implement this feature (assign to yourself).
- [ ] Someone else should implement this (describe it well).
Feature description
This feature is about adding bpf_attach event.
This event will indicate bpf program being attached to a system event (kprobe, tracepoint, etc.).
This event will be then used in signatures.