aa-ebpf 0.0.1-alpha.8

eBPF-based kernel-level monitoring hooks for Agent Assembly
1
2
3
4
//! Kprobe handler for `sys_rename`.
//!
//! Intercepts file rename/move operations to detect attempts to relocate
//! sensitive files or disguise unauthorized file modifications.