kprobe exec

[root@localhost tracing]# echo 1 > events/sched/sched_process_exec/enable
[root@localhost tracing]# cat trace_pipe
           clear-1027179 [004] .... 3718151.637187: sched_process_exec: filename=/usr/bin/clear pid=1027179 old_pid=1027179
             cat-1027180 [000] .... 3718155.636730: sched_process_exec: filename=/usr/bin/cat pid=1027180 old_pid=1027180
            runc-1027181 [005] .... 3718157.266166: sched_process_exec: filename=/usr/bin/runc pid=1027181 old_pid=1027181
            runc-1027187 [001] .... 3718157.358003: sched_process_exec: filename=/usr/bin/runc pid=1027187 old_pid=1027187
            runc-1027192 [001] .... 3718157.441191: sched_process_exec: filename=/usr/bin/runc pid=1027192 old_pid=1027192

猜你喜欢

转载自blog.csdn.net/SHELLCODE_8BIT/article/details/131228361