ptrace kprobe

echo 'p:ptrace_kprobe sys_ptrace request=%di:u64 ptrace_pid=%si:u64 addr=%dx:u64' > /sys/kernel/debug/tracing/kprobe_events
echo 1 > /sys/kernel/debug/tracing/events/kprobes/ptrace_kprobe/enable
echo > /sys/kernel/debug/tracing/trace&&cat /sys/kernel/debug/tracing/trace

猜你喜欢

转载自blog.csdn.net/SHELLCODE_8BIT/article/details/131107956