• @[email protected]
    link
    fedilink
    English
    12 months ago

    No, you make a management API for security products that run in user space as root, you don’t use kernel modules.

      • @[email protected]
        link
        fedilink
        English
        1
        edit-2
        2 months ago

        Currently, cloudstrike offers two methods for Linux: a kernel driver / module and a theoretically safer alternative using epbf (you could call that “kernel level scripting”). Ironically, they triggered a kernel bug using that second option. They did not test all kernels they listed as compatible or something like that.