Higher level events #1105
Replies: 3 comments
-
related: #1115 |
Beta Was this translation helpful? Give feedback.
-
Another important aspect that I forgot, is flags that modify the event schema (e.g |
Beta Was this translation helpful? Give feedback.
-
related: #1170 |
Beta Was this translation helpful? Give feedback.
-
This is not a new idea, we have discussed it in the past but it's wasn't yet articulated. The idea is to create higher level events that abstracts the kernel events and makes them more usable for the user. For example: instead of using execve, security_bprm_check or sched_process_exec, the user use an event called “exec” that contains all the relevant information.
Motivation:
Beta Was this translation helpful? Give feedback.
All reactions