This repository contains several of the tools used for event collection across the Carbon Black Cloud Linux agent.
- kernel_event_collector_module: Kernel-based collection module for use on RHEL 6/7/8 distributions
- bpf_probe: eBPF-based collector for Linux 4.4+ kernels that support BPF
- app_control_event_kernel_module: Access controls via userspace and event collection
The kernel-event-collector-module project team welcomes contributions from the community. Before you start working with kernel-event-collector-module, please read our Developer Certificate of Origin. All contributions to this repository must be signed as described on that page. Your signature certifies that you wrote the patch or have the right to pass it on as an open-source patch. For more detailed information, refer to CONTRIBUTING.md.
See LICENSE.txt