Catching ransomware with eBPF: what execve/openat tracing taught me about false positives
DEV Community
Catching ransomware with eBPF: what execve/openat tracing taught me about false positives
Lessons from building talus-process-monitor, a Rust + eBPF ransomware detector: per-CPU perf buffers, behavioural pattern matching, and why build systems are a detector's worst enemy.
0 comments
No comments yet.