• zorro@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    9 days ago

    Probably going to be written as eBPF which is what all the corpo antivirus stuff does today.

    Doesn’t need to be added to the kernel, you can load kernel code in from user level at runtime.

    https://ebpf.io/what-is-ebpf/