How to trace exec() syscall using eBPF/BCC script?
Issue
- How to trace
exec()
syscall using eBPF/BCC script? - How to trace new processes via exec() syscalls?
Environment
- Red Hat Enterprise Linux 7.6+
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- bcc-tools
- execsnoop
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.