You need to use the findings and automate based on those. eBPF is not enough.
eBPF isn't enough. I spoke with a security leader recently who told me he was running over a dozen eBPF agents in production. 🕵🏻♂️🕵🏻♂️🕵🏻♂️🕵🏻♂️🕵🏻♂️🕵🏻♂️🕵🏻♂️🕵🏻♂️🕵🏻♂️ Each agent he added made his engineering team more and more anxious about the risk of breaking their apps. To make matters worse, none of his agents could actually stop application attacks 🚫🔒. They could only alert on findings, which created more work for his appsec team, already small and overworked 😩. In 2024, eBPF is an observability solution, not a security solution. Agents need more than just eBPF.