About systemcall #2945
Replies: 3 comments 23 replies
-
@skandbug Thanks for loving tracee.
Please, try like this:
And running ls in other terminal tracee will output this:
For more see: https://aquasecurity.github.io/tracee/dev/docs/filters/filtering/ Closing as not an issue, but feel free to ask. |
Beta Was this translation helpful? Give feedback.
-
However, if you trace an executable program, the system calls are not fixed. |
Beta Was this translation helpful? Give feedback.
-
@skandbug you can use the "syscalls" set to get what you want, simply add the following filter: |
Beta Was this translation helpful? Give feedback.
-
Tracee is a great tool. But I don't know how to get the system calls that the program runs through her.
e.g.,:
ls command's: execve,brk,arch_prctl,mmap....
Beta Was this translation helpful? Give feedback.
All reactions