eBPF is restricted when booted in a SB environment, but it's not nonfunctional. The default config puts the kernel into "integrity" mode of Kernel Lockdown, which reduces scope of access and enforces read-only usage.
Whether or not the specific functions needed to replicate this tool are impacted is beyond my knowledge.
rlmp_89|3 months ago
-> voila!
arcanemachiner|3 months ago
mentalgear|3 months ago
curcbit|3 months ago
oneshtein|3 months ago
mroche|3 months ago
Whether or not the specific functions needed to replicate this tool are impacted is beyond my knowledge.
grigio|3 months ago