Awesome paper about Linux offensive/defensive eBPF internals. Make no mistake, the future of advanced Linux attacks, container escapes and rootkits is eBPF. Importantly, all Linux EDRs are also based on eBPF ^^ double-edged sword as I mentioned in the past https://t.co/Wej4ovV1Ov