Implementing Ebpf Security Monitoring

Use when implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.

oyi77 58aa9e6 4.3 KB Updated 10 repo stars

File contents

oyi77/1ai-skills/tree/main/cybersecurity/implementing-ebpf-security-monitoring commit 58aa9e60d0

Frequently asked questions

npx skillmds add oyi77/implementing-ebpf-security-monitoring