Ebpf Sec Mon

Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.

undermybelt Updated

File contents

undermybelt/hermes-skills/tree/main/skills/red-teaming/anthropic-cybersecurity-skills/skills/ebpf-sec-mon commit 57908974b6

Frequently asked questions

npx skillmds@latest add undermybelt/ebpf-sec-mon