3 ms·
If someone has root, it's already game over. An attacker could just hook the syscalls directly which would be more stealthy that using BPF programs.
by allset_ 7y ago
If someone has root, it's already game over. An attacker could just hook the syscalls directly which would be more stealthy that using BPF programs.