aa-ebpf 0.0.1-alpha.8

eBPF-based kernel-level monitoring hooks for Agent Assembly
1
2
3
4
//! Kprobe handler for `sys_unlink`.
//!
//! Intercepts file deletion operations to detect evidence destruction
//! (e.g., deleting audit logs) or unauthorized file removal.