An on-device eBPF system that attributes security-relevant kernel events — network egress, credential-adjacent file access, process lifecycle — to installed Android packages rather than to PIDs or UIDs.
android rust linux-kernel provenance android-kernel ebpf android-security process-monitoring security-research runtime-security kernel-tracing kernel-security
-
Updated
Aug 26, 2026 - Rust