Earlier quoted context omitted.
> The remaining challenge is how does one work backwards and see what occurred? How would you work backwards to see what occurred if you'd run a malicious script/binary as root? The launching of an eBPF thing would leave the same traces and non-traces, right? And if there's a way to introspect all running eBPF things, it might be harder for an eBPF thing to hide itself, due to my assumed limitations of the eBPF runti…
For other things such as a malicious script I would use SELinux, IPTables owner module and auditd to see what is going on and to limit what can be done. This assumes one removes the unconfined_t types and assumes a file if running as root. None of those things dynamically execute code by design. That said my question is around file-less behavior and monitoring. As far as I can tell there is zero monitoring unless to…
Re: eBPF for tracing how Firefox uses page faults to load libraries
#21To answer my own question it appears the only option is to recompile the kernel to disable BPF.