summaryrefslogtreecommitdiff
path: root/bpftrace-checkping
blob: 2b99c7b3cd585b683fab86b44c6043947c736ab4 (plain)
1
sudo bpftrace -e 'tracepoint:syscalls:sys_enter_execve { $f = str(args->filename); if ($f == "/usr/bin/ping" || $f == "/bin/ping") { printf("PID %d (%s) executed ping\n", pid, comm); } }'