Lines Matching full:execsnoop
1 .TH execsnoop 8 "2020-02-20" "USER COMMANDS"
3 execsnoop \- Trace new processes via exec() syscalls. Uses Linux eBPF/bcc.
5 .B execsnoop [\-h] [\-T] [\-t] [\-x] [\-\-cgroupmap CGROUPMAP] [\-\-mntnsmap MAPPATH]
8 execsnoop traces new processes, showing the filename executed and argument
14 exec(), eg, for worker processes, which won't be included in the execsnoop
69 .B execsnoop
73 .B execsnoop \-t
77 .B execsnoop \-U
81 .B execsnoop \-u 1000
85 .B execsnoop \-Uu root
89 .B execsnoop \-x
93 .B execsnoop \-q
97 .B execsnoop \-n mount
101 .B execsnoop \-l testpkg
105 .B execsnoop \-\-cgroupmap /sys/fs/bpf/test01