Back to Falco

eBPF Probe

content/en/docs/reference/glossary/ebpf-probe.md

latest220 B
Original Source

The eBPF probe (deprecated) collects syscall events from the {{< glossary_tooltip text="kernel" term_id="kernel" >}}, as the {{< glossary_tooltip text="kernel module" term_id="kernel-module-driver" >}} does.

<!--more-->