summaryrefslogtreecommitdiff
path: root/bpftrace-execve
blob: 983aa7670cebaf20e7e414eaef8995d3cb8ad000 (plain)
1
sudo bpftrace -e 'tracepoint:syscalls:sys_enter_execve { printf("PID: %d, UID: %d, CMD: %s, TIME: %u, FILE: %s\n", pid,  uid, comm, nsecs, str(args->filename)); }'