cilium/tetragon ? reverse-engineered prompt
Reverse engineered prompt
Build me a security monitoring tool for Linux and Kubernetes that watches what processes are doing in real time and can react when something looks suspicious.
I want it to track process start and stop events by default, and also support deeper tracing for things like system calls, network activity, file access, and credential related actions. When it runs in Kubernetes, it should understand pods, namespaces, and workloads so the alerts and logs are tied to the right app. I’d like a simple command line experience to view the events, plus a way to define policies for what to observe and when to enforce something.
Make it feel production ready, with clear docs, example configs, and a straightforward install path for Linux and Kubernetes. If you need current details for how to wire up eBPF or Kubernetes integration, look up the latest docs online as you build it.
Are you gonna build this?
make sure you review the code using coderabbit