__ __ __ __ _____ _ _ _____ _ _ _ | \/ | \ \ / / | __ \ (_) | | / ____| | | | | | \ / |_ __\ V / | |__) | __ ___ ____ _| |_ ___ | (___ | |__ ___| | | | |\/| | '__|> < | ___/ '__| \ \ / / _` | __/ _ \ \___ \| '_ \ / _ \ | | | | | | |_ / . \ | | | | | |\ V / (_| | || __/ ____) | | | | __/ | | |_| |_|_(_)_/ \_\ |_| |_| |_| \_/ \__,_|\__\___| |_____/|_| |_|\___V 2.1 if you need WebShell for Seo everyday contact me on Telegram Telegram Address : @jackleetFor_More_Tools:
#! /usr/bin/python3
# @lint-avoid-python-3-compatibility-imports
#
# execsnoop Trace new processes via exec() syscalls.
# For Linux, uses BCC, eBPF. Embedded C.
#
# USAGE: execsnoop [-h] [-T] [-t] [-x] [--cgroupmap CGROUPMAP]
# [--mntnsmap MNTNSMAP] [-u USER] [-q] [-n NAME] [-l LINE]
# [-U] [--max-args MAX_ARGS] [-P PPID]
#
# This currently will print up to a maximum of 19 arguments, plus the process
# name, so 20 fields in total (MAXARG).
#
# This won't catch all new processes: an application may fork() but not exec().
#
# Copyright 2016 Netflix, Inc.
# Licensed under the Apache License, Version 2.0 (the "License")
#
# 07-Feb-2016 Brendan Gregg Created this.
# 11-Aug-2022 Rocky Xing Added PPID filter support.
from __future__ import print_function
from bcc import BPF
from bcc.containers import filter_by_containers
from bcc.utils import ArgString, printb
import argparse
import re
import time
import pwd
from collections import defaultdict
from time import strftime
def parse_uid(user):
try:
result = int(user)
except ValueError:
try:
user_info = pwd.getpwnam(user)
except KeyError:
raise argparse.ArgumentTypeError(
"{0!r} is not valid UID or user entry".format(user))
else:
return user_info.pw_uid
else:
# Maybe validate if UID < 0 ?
return result
# arguments
examples = """examples:
./execsnoop # trace all exec() syscalls
./execsnoop -x # include failed exec()s
./execsnoop -T # include time (HH:MM:SS)
./execsnoop -P 181 # only trace new processes whose parent PID is 181
./execsnoop -U # include UID
./execsnoop -C # include CPU
./execsnoop -u 1000 # only trace UID 1000
./execsnoop -u user # get user UID and trace only them
./execsnoop -t # include timestamps
./execsnoop -q # add "quotemarks" around arguments
./execsnoop -n main # only print command lines containing "main"
./execsnoop -l tpkg # only print command where arguments contains "tpkg"
./execsnoop --cgroupmap mappath # only trace cgroups in this BPF map
./execsnoop --mntnsmap mappath # only trace mount namespaces in the map
"""
parser = argparse.ArgumentParser(
description="Trace exec() syscalls",
formatter_class=argparse.RawDescriptionHelpFormatter,
epilog=examples)
parser.add_argument("-T", "--time", action="store_true",
help="include time column on output (HH:MM:SS)")
parser.add_argument("-t", "--timestamp", action="store_true",
help="include timestamp on output")
parser.add_argument("-x", "--fails", action="store_true",
help="include failed exec()s")
parser.add_argument("--cgroupmap",
help="trace cgroups in this BPF map only")
parser.add_argument("--mntnsmap",
help="trace mount namespaces in this BPF map only")
parser.add_argument("-u", "--uid", type=parse_uid, metavar='USER',
help="trace this UID only")
parser.add_argument("-q", "--quote", action="store_true",
help="Add quotemarks (\") around arguments."
)
parser.add_argument("-n", "--name",
type=ArgString,
help="only print commands matching this name (regex), any arg")
parser.add_argument("-l", "--line",
type=ArgString,
help="only print commands where arg contains this line (regex)")
parser.add_argument("-U", "--print-uid", action="store_true",
help="print UID column")
parser.add_argument("-C", "--print-cpu", action="store_true",
help="print CPU column")
parser.add_argument("--max-args", default="20",
help="maximum number of arguments parsed and displayed, defaults to 20")
parser.add_argument("-P", "--ppid",
help="trace this parent PID only")
parser.add_argument("--ebpf", action="store_true",
help=argparse.SUPPRESS)
args = parser.parse_args()
def check_cpu_filed():
# Define the bpf program for checking purpose
#if LINUX_VERSION_CODE < KERNEL_VERSION(5,16,0)
filed_in_task_struct = True
#else
filed_in_task_struct = False
#endif
return filed_in_task_struct
# define BPF program
bpf_text = """
#include <uapi/linux/ptrace.h>
#include <linux/sched.h>
#include <linux/fs.h>
#define ARGSIZE 128
enum event_type {
EVENT_ARG,
EVENT_RET,
};
struct data_t {
u32 pid; // PID as in the userspace term (i.e. task->tgid in kernel)
u32 ppid; // Parent PID as in the userspace term (i.e task->real_parent->tgid in kernel)
u32 uid;
u32 cpu;
char comm[TASK_COMM_LEN];
enum event_type type;
char argv[ARGSIZE];
int retval;
};
BPF_PERF_OUTPUT(events);
static int __submit_arg(struct pt_regs *ctx, void *ptr, struct data_t *data)
{
bpf_probe_read_user(data->argv, sizeof(data->argv), ptr);
events.perf_submit(ctx, data, sizeof(struct data_t));
return 1;
}
static int submit_arg(struct pt_regs *ctx, void *ptr, struct data_t *data)
{
const char *argp = NULL;
bpf_probe_read_user(&argp, sizeof(argp), ptr);
if (argp) {
return __submit_arg(ctx, (void *)(argp), data);
}
return 0;
}
int syscall__execve(struct pt_regs *ctx,
const char __user *filename,
const char __user *const __user *__argv,
const char __user *const __user *__envp)
{
u32 uid = bpf_get_current_uid_gid() & 0xffffffff;
UID_FILTER
if (container_should_be_filtered()) {
return 0;
}
// create data here and pass to submit_arg to save stack space (#555)
struct data_t data = {};
struct task_struct *task;
data.pid = bpf_get_current_pid_tgid() >> 32;
task = (struct task_struct *)bpf_get_current_task();
// Some kernels, like Ubuntu 4.13.0-generic, return 0
// as the real_parent->tgid.
// We use the get_ppid function as a fallback in those cases. (#1883)
data.ppid = task->real_parent->tgid;
PPID_FILTER
bpf_get_current_comm(&data.comm, sizeof(data.comm));
data.type = EVENT_ARG;
__submit_arg(ctx, (void *)filename, &data);
// skip first arg, as we submitted filename
#pragma unroll
for (int i = 1; i < MAXARG; i++) {
if (submit_arg(ctx, (void *)&__argv[i], &data) == 0)
goto out;
}
// handle truncated argument list
char ellipsis[] = "...";
__submit_arg(ctx, (void *)ellipsis, &data);
out:
return 0;
}
int do_ret_sys_execve(struct pt_regs *ctx)
{
if (container_should_be_filtered()) {
return 0;
}
struct data_t data = {};
struct task_struct *task;
u32 uid = bpf_get_current_uid_gid() & 0xffffffff;
UID_FILTER
data.pid = bpf_get_current_pid_tgid() >> 32;
data.uid = uid;
task = (struct task_struct *)bpf_get_current_task();
// Some kernels, like Ubuntu 4.13.0-generic, return 0
// as the real_parent->tgid.
// We use the get_ppid function as a fallback in those cases. (#1883)
data.ppid = task->real_parent->tgid;
data.cpu = CPU_RUNNING_ON;
PPID_FILTER
bpf_get_current_comm(&data.comm, sizeof(data.comm));
data.type = EVENT_RET;
data.retval = PT_REGS_RC(ctx);
events.perf_submit(ctx, &data, sizeof(data));
return 0;
}
"""
bpf_text = bpf_text.replace("MAXARG", args.max_args)
if args.uid:
bpf_text = bpf_text.replace('UID_FILTER',
'if (uid != %s) { return 0; }' % args.uid)
else:
bpf_text = bpf_text.replace('UID_FILTER', '')
if args.ppid:
bpf_text = bpf_text.replace('PPID_FILTER',
'if (data.ppid != %s) { return 0; }' % args.ppid)
else:
bpf_text = bpf_text.replace('PPID_FILTER', '')
# CPU field moved back into thread_info since commit bcf9033e5449(linux 5.16)
# Use BTF for CPU field checks if available, otherwise use LINUX_VERSION_CODE checking.
if BPF.kernel_struct_has_field(b'task_struct', b'cpu') == 1 \
or check_cpu_filed():
bpf_text = bpf_text.replace('CPU_RUNNING_ON', 'task->cpu')
else:
bpf_text = bpf_text.replace('CPU_RUNNING_ON', 'task->thread_info.cpu')
bpf_text = filter_by_containers(args) + bpf_text
if args.ebpf:
print(bpf_text)
exit()
# initialize BPF
b = BPF(text=bpf_text)
execve_fnname = b.get_syscall_fnname("execve")
b.attach_kprobe(event=execve_fnname, fn_name="syscall__execve")
b.attach_kretprobe(event=execve_fnname, fn_name="do_ret_sys_execve")
# header
if args.time:
print("%-9s" % ("TIME"), end="")
if args.timestamp:
print("%-8s" % ("TIME(s)"), end="")
if args.print_uid:
print("%-6s" % ("UID"), end="")
if args.print_cpu:
print("%-16s %-7s %-7s %-4s %3s %s" % ("PCOMM", "PID", "PPID", "CPU", "RET", "ARGS"))
else:
print("%-16s %-7s %-7s %3s %s" % ("PCOMM", "PID", "PPID", "RET", "ARGS"))
class EventType(object):
EVENT_ARG = 0
EVENT_RET = 1
start_ts = time.time()
argv = defaultdict(list)
# This is best-effort PPID matching. Short-lived processes may exit
# before we get a chance to read the PPID.
# This is a fallback for when fetching the PPID from task->real_parent->tgip
# returns 0, which happens in some kernel versions.
def get_ppid(pid):
try:
with open("/proc/%d/status" % pid) as status:
for line in status:
if line.startswith("PPid:"):
return int(line.split()[1])
except IOError:
pass
return 0
# process event
def print_event(cpu, data, size):
event = b["events"].event(data)
skip = False
if event.type == EventType.EVENT_ARG:
argv[event.pid].append(event.argv)
elif event.type == EventType.EVENT_RET:
if event.retval != 0 and not args.fails:
skip = True
if args.name and not re.search(bytes(args.name), event.comm):
skip = True
if args.line and not re.search(bytes(args.line),
b' '.join(argv[event.pid])):
skip = True
if args.quote:
argv[event.pid] = [
b"\"" + arg.replace(b"\"", b"\\\"") + b"\""
for arg in argv[event.pid]
]
if not skip:
if args.time:
printb(b"%-9s" % strftime("%H:%M:%S").encode('ascii'), nl="")
if args.timestamp:
printb(b"%-8.3f" % (time.time() - start_ts), nl="")
if args.print_uid:
printb(b"%-6d" % event.uid, nl="")
ppid = event.ppid if event.ppid > 0 else get_ppid(event.pid)
ppid = b"%d" % ppid if ppid > 0 else b"?"
argv_text = b' '.join(argv[event.pid]).replace(b'\n', b'\\n')
if args.print_cpu:
printb(b"%-16s %-7d %-7s %-4d %3d %s" % (event.comm, event.pid,
ppid, event.cpu, event.retval, argv_text))
else:
printb(b"%-16s %-7d %-7s %3d %s" % (event.comm, event.pid,
ppid, event.retval, argv_text))
try:
del(argv[event.pid])
except Exception:
pass
# loop with callback to print_event
b["events"].open_perf_buffer(print_event)
while 1:
try:
b.perf_buffer_poll()
except KeyboardInterrupt:
exit()
| Name | Type | Size | Permission | Actions |
|---|---|---|---|---|
| ModemManager | File | 2.3 MB | 0755 |
|
| NetworkManager | File | 4.02 MB | 0755 |
|
| a2disconf | File | 15.75 KB | 0755 |
|
| a2dismod | File | 15.75 KB | 0755 |
|
| a2dissite | File | 15.75 KB | 0755 |
|
| a2enconf | File | 15.75 KB | 0755 |
|
| a2enmod | File | 15.75 KB | 0755 |
|
| a2ensite | File | 15.75 KB | 0755 |
|
| a2query | File | 9.6 KB | 0755 |
|
| aa-load | File | 38.81 KB | 0755 |
|
| aa-remove-unknown | File | 3.15 KB | 0755 |
|
| aa-status | File | 43.14 KB | 0755 |
|
| aa-teardown | File | 137 B | 0755 |
|
| accessdb | File | 14.63 KB | 0755 |
|
| add-shell | File | 1.03 KB | 0755 |
|
| addgnupghome | File | 3 KB | 0755 |
|
| addgroup | File | 53.9 KB | 0755 |
|
| adduser | File | 53.9 KB | 0755 |
|
| agetty | File | 67.64 KB | 0755 |
|
| alsa | File | 5.45 KB | 0755 |
|
| alsa-info | File | 29.29 KB | 0755 |
|
| alsabat-test | File | 4.04 KB | 0755 |
|
| alsactl | File | 131.67 KB | 0755 |
|
| anacron | File | 34.25 KB | 0755 |
|
| apache2 | File | 828.66 KB | 0755 |
|
| apache2ctl | File | 7.26 KB | 0755 |
|
| apachectl | File | 7.26 KB | 0755 |
|
| apparmor_parser | File | 1.7 MB | 0755 |
|
| apparmor_status | File | 43.14 KB | 0755 |
|
| applygnupgdefaults | File | 2.17 KB | 0755 |
|
| aptd | File | 1.36 KB | 0755 |
|
| argdist-bpfcc | File | 36 KB | 0755 |
|
| arp | File | 65.69 KB | 0755 |
|
| arpd | File | 26.41 KB | 0755 |
|
| arptables | File | 271.37 KB | 0755 |
|
| arptables-nft | File | 271.37 KB | 0755 |
|
| arptables-nft-restore | File | 271.37 KB | 0755 |
|
| arptables-nft-save | File | 271.37 KB | 0755 |
|
| arptables-restore | File | 271.37 KB | 0755 |
|
| arptables-save | File | 271.37 KB | 0755 |
|
| arptables-translate | File | 271.37 KB | 0755 |
|
| aspell-autobuildhash | File | 13.39 KB | 0755 |
|
| avahi-daemon | File | 150.32 KB | 0755 |
|
| badblocks | File | 34.39 KB | 0755 |
|
| bashreadline-bpfcc | File | 2.7 KB | 0755 |
|
| bashreadline.bt | File | 698 B | 0755 |
|
| bindsnoop-bpfcc | File | 15.96 KB | 0755 |
|
| biolatency-bpfcc | File | 11.1 KB | 0755 |
|
| biolatency-kp.bt | File | 704 B | 0755 |
|
| biolatency.bt | File | 681 B | 0755 |
|
| biolatpcts-bpfcc | File | 10.01 KB | 0755 |
|
| biopattern-bpfcc | File | 3.86 KB | 0755 |
|
| biosdecode | File | 27.28 KB | 0755 |
|
| biosnoop-bpfcc | File | 10.58 KB | 0755 |
|
| biosnoop.bt | File | 1.12 KB | 0755 |
|
| biostacks.bt | File | 955 B | 0755 |
|
| biotop-bpfcc | File | 9.41 KB | 0755 |
|
| bitesize-bpfcc | File | 1.14 KB | 0755 |
|
| bitesize.bt | File | 567 B | 0755 |
|
| blkdeactivate | File | 15.97 KB | 0755 |
|
| blkdiscard | File | 22.45 KB | 0755 |
|
| blkid | File | 54.49 KB | 0755 |
|
| blkzone | File | 34.45 KB | 0755 |
|
| blockdev | File | 34.45 KB | 0755 |
|
| bluetoothd | File | 1.75 MB | 0755 |
|
| bpflist-bpfcc | File | 2.54 KB | 0755 |
|
| bpftool | File | 2.02 MB | 0755 |
|
| bridge | File | 156.56 KB | 0755 |
|
| brltty-setup | File | 1.38 KB | 0755 |
|
| btrfsdist-bpfcc | File | 6.47 KB | 0755 |
|
| btrfsslower-bpfcc | File | 9.75 KB | 0755 |
|
| cachestat-bpfcc | File | 6.38 KB | 0755 |
|
| cachetop-bpfcc | File | 9.15 KB | 0755 |
|
| capable-bpfcc | File | 8.28 KB | 0755 |
|
| capable.bt | File | 1.88 KB | 0755 |
|
| capsh | File | 57.2 KB | 0755 |
|
| cfdisk | File | 98.81 KB | 0755 |
|
| cgdisk | File | 166.56 KB | 0755 |
|
| chat | File | 34.38 KB | 0755 |
|
| chcpu | File | 34.45 KB | 0755 |
|
| check_forensic | File | 952 B | 0755 |
|
| chgpasswd | File | 58.45 KB | 0755 |
|
| chmem | File | 38.45 KB | 0755 |
|
| chpasswd | File | 75.16 KB | 0755 |
|
| chroot | File | 42.59 KB | 0755 |
|
| cobjnew-bpfcc | File | 53 B | 0755 |
|
| coldreboot | File | 99 B | 0755 |
|
| compactsnoop-bpfcc | File | 11.08 KB | 0755 |
|
| cpudist-bpfcc | File | 6.85 KB | 0755 |
|
| cpuunclaimed-bpfcc | File | 14.59 KB | 0755 |
|
| cpuwalk.bt | File | 497 B | 0755 |
|
| cracklib-check | File | 14.23 KB | 0755 |
|
| cracklib-format | File | 231 B | 0755 |
|
| cracklib-packer | File | 14.23 KB | 0755 |
|
| cracklib-unpacker | File | 14.23 KB | 0755 |
|
| create-cracklib-dict | File | 990 B | 0755 |
|
| criticalstat-bpfcc | File | 8.41 KB | 0755 |
|
| cron | File | 70.75 KB | 0755 |
|
| cups-browsed | File | 214.78 KB | 0755 |
|
| cupsaccept | File | 14.38 KB | 0755 |
|
| cupsctl | File | 14.45 KB | 0755 |
|
| cupsd | File | 502.93 KB | 0755 |
|
| cupsdisable | File | 14.38 KB | 0755 |
|
| cupsenable | File | 14.38 KB | 0755 |
|
| cupsfilter | File | 46.66 KB | 0755 |
|
| cupsreject | File | 14.38 KB | 0755 |
|
| dbconfig-generate-include | File | 12.36 KB | 0755 |
|
| dbconfig-load-include | File | 5.57 KB | 0755 |
|
| dbslower-bpfcc | File | 7.22 KB | 0755 |
|
| dbstat-bpfcc | File | 3.7 KB | 0755 |
|
| dcb | File | 104.59 KB | 0755 |
|
| dcsnoop-bpfcc | File | 4.03 KB | 0755 |
|
| dcsnoop.bt | File | 1.23 KB | 0755 |
|
| dcstat-bpfcc | File | 3.77 KB | 0755 |
|
| deadlock-bpfcc | File | 20.45 KB | 0755 |
|
| debugfs | File | 237.95 KB | 0755 |
|
| delgroup | File | 18.53 KB | 0755 |
|
| deluser | File | 18.53 KB | 0755 |
|
| depmod | File | 194.31 KB | 0755 |
|
| devlink | File | 186.94 KB | 0755 |
|
| dhcpcd | File | 479.49 KB | 0755 |
|
| dirtop-bpfcc | File | 8.37 KB | 0755 |
|
| dmidecode | File | 143.42 KB | 0755 |
|
| dmsetup | File | 162.34 KB | 0755 |
|
| dmstats | File | 162.34 KB | 0755 |
|
| dnsmasq | File | 580.52 KB | 0755 |
|
| dosfsck | File | 98.46 KB | 0755 |
|
| dosfslabel | File | 42.46 KB | 0755 |
|
| dpkg-preconfigure | File | 4.46 KB | 0755 |
|
| dpkg-reconfigure | File | 4.43 KB | 0755 |
|
| drsnoop-bpfcc | File | 6.73 KB | 0755 |
|
| dump.exfat | File | 22.52 KB | 0755 |
|
| dumpe2fs | File | 34.38 KB | 0755 |
|
| e2freefrag | File | 18.38 KB | 0755 |
|
| e2fsck | File | 408.57 KB | 0755 |
|
| e2image | File | 42.46 KB | 0755 |
|
| e2label | File | 114.64 KB | 0755 |
|
| e2mmpstatus | File | 34.38 KB | 0755 |
|
| e2scrub | File | 7.36 KB | 0755 |
|
| e2scrub_all | File | 4.91 KB | 0755 |
|
| e2undo | File | 22.38 KB | 0755 |
|
| e4crypt | File | 30.45 KB | 0755 |
|
| e4defrag | File | 34.38 KB | 0755 |
|
| ebtables | File | 271.37 KB | 0755 |
|
| ebtables-nft | File | 271.37 KB | 0755 |
|
| ebtables-nft-restore | File | 271.37 KB | 0755 |
|
| ebtables-nft-save | File | 271.37 KB | 0755 |
|
| ebtables-restore | File | 271.37 KB | 0755 |
|
| ebtables-save | File | 271.37 KB | 0755 |
|
| ebtables-translate | File | 271.37 KB | 0755 |
|
| ethtool | File | 731.77 KB | 0755 |
|
| execsnoop-bpfcc | File | 10.93 KB | 0755 |
|
| execsnoop.bt | File | 928 B | 0755 |
|
| exfat2img | File | 34.52 KB | 0755 |
|
| exfatlabel | File | 26.55 KB | 0755 |
|
| exitsnoop-bpfcc | File | 9.42 KB | 0755 |
|
| ext4dist-bpfcc | File | 6.53 KB | 0755 |
|
| ext4slower-bpfcc | File | 9.71 KB | 0755 |
|
| f2fsslower-bpfcc | File | 10.52 KB | 0755 |
|
| faillock | File | 22.38 KB | 0755 |
|
| fatlabel | File | 42.46 KB | 0755 |
|
| fdisk | File | 118.5 KB | 0755 |
|
| filefrag | File | 18.39 KB | 0755 |
|
| filegone-bpfcc | File | 5.64 KB | 0755 |
|
| filelife-bpfcc | File | 6.38 KB | 0755 |
|
| fileslower-bpfcc | File | 7.2 KB | 0755 |
|
| filetop-bpfcc | File | 6.35 KB | 0755 |
|
| findfs | File | 14.45 KB | 0755 |
|
| fixparts | File | 58.55 KB | 0755 |
|
| fsck | File | 42.42 KB | 0755 |
|
| fsck.btrfs | File | 1.16 KB | 0755 |
|
| fsck.exfat | File | 71.34 KB | 0755 |
|
| fsck.ext2 | File | 408.57 KB | 0755 |
|
| fsck.ext3 | File | 408.57 KB | 0755 |
|
| fsck.ext4 | File | 408.57 KB | 0755 |
|
| fsck.fat | File | 98.46 KB | 0755 |
|
| fsck.msdos | File | 98.46 KB | 0755 |
|
| fsck.vfat | File | 98.46 KB | 0755 |
|
| fsfreeze | File | 14.45 KB | 0755 |
|
| fstab-decode | File | 14.38 KB | 0755 |
|
| fstrim | File | 42.45 KB | 0755 |
|
| funccount-bpfcc | File | 12.68 KB | 0755 |
|
| funcinterval-bpfcc | File | 5.46 KB | 0755 |
|
| funclatency-bpfcc | File | 11.28 KB | 0755 |
|
| funcslower-bpfcc | File | 10.38 KB | 0755 |
|
| gdisk | File | 198.56 KB | 0755 |
|
| gdm3 | File | 446.8 KB | 0755 |
|
| genl | File | 138.66 KB | 0755 |
|
| getcap | File | 14.38 KB | 0755 |
|
| gethostlatency-bpfcc | File | 3.82 KB | 0755 |
|
| gethostlatency.bt | File | 1.23 KB | 0755 |
|
| getpcaps | File | 14.38 KB | 0755 |
|
| getty | File | 67.64 KB | 0755 |
|
| getweb | File | 13.67 KB | 0755 |
|
| gnome-menus-blacklist | File | 2.23 KB | 0755 |
|
| gparted | File | 7.38 KB | 0755 |
|
| groupadd | File | 75.29 KB | 0755 |
|
| groupdel | File | 67.04 KB | 0755 |
|
| groupmod | File | 71.2 KB | 0755 |
|
| grpck | File | 58.45 KB | 0755 |
|
| grpconv | File | 50.32 KB | 0755 |
|
| grpunconv | File | 50.29 KB | 0755 |
|
| grub-install | File | 1.18 MB | 0755 |
|
| grub-macbless | File | 954.49 KB | 0755 |
|
| grub-mkconfig | File | 8.63 KB | 0755 |
|
| grub-mkdevicemap | File | 70.77 KB | 0755 |
|
| grub-probe | File | 962.74 KB | 0755 |
|
| grub-reboot | File | 4.73 KB | 0755 |
|
| grub-set-default | File | 3.47 KB | 0755 |
|
| halt | File | 299 KB | 0755 |
|
| hardirqs-bpfcc | File | 6.85 KB | 0755 |
|
| hdparm | File | 139.43 KB | 0755 |
|
| httxt2dbm | File | 14.38 KB | 0755 |
|
| iconvconfig | File | 34.55 KB | 0755 |
|
| ifconfig | File | 85.25 KB | 0755 |
|
| init | File | 134.45 KB | 0755 |
|
| inject-bpfcc | File | 16.06 KB | 0755 |
|
| insmod | File | 194.31 KB | 0755 |
|
| install-sgmlcatalog | File | 4.44 KB | 0755 |
|
| installkernel | File | 2.62 KB | 0755 |
|
| invoke-rc.d | File | 16.13 KB | 0755 |
|
| ip | File | 904.97 KB | 0755 |
|
| ip6tables | File | 271.37 KB | 0755 |
|
| ip6tables-apply | File | 6.89 KB | 0755 |
|
| ip6tables-legacy | File | 105.02 KB | 0755 |
|
| ip6tables-legacy-restore | File | 105.02 KB | 0755 |
|
| ip6tables-legacy-save | File | 105.02 KB | 0755 |
|
| ip6tables-nft | File | 271.37 KB | 0755 |
|
| ip6tables-nft-restore | File | 271.37 KB | 0755 |
|
| ip6tables-nft-save | File | 271.37 KB | 0755 |
|
| ip6tables-restore | File | 271.37 KB | 0755 |
|
| ip6tables-restore-translate | File | 271.37 KB | 0755 |
|
| ip6tables-save | File | 271.37 KB | 0755 |
|
| ip6tables-translate | File | 271.37 KB | 0755 |
|
| ipmaddr | File | 18.38 KB | 0755 |
|
| ipp-usb | File | 6.66 MB | 0755 |
|
| ippevepcl | File | 18.38 KB | 0755 |
|
| ippeveprinter | File | 186.46 KB | 0755 |
|
| ippeveps | File | 30.38 KB | 0755 |
|
| iptables | File | 271.37 KB | 0755 |
|
| iptables-apply | File | 6.89 KB | 0755 |
|
| iptables-legacy | File | 105.02 KB | 0755 |
|
| iptables-legacy-restore | File | 105.02 KB | 0755 |
|
| iptables-legacy-save | File | 105.02 KB | 0755 |
|
| iptables-nft | File | 271.37 KB | 0755 |
|
| iptables-nft-restore | File | 271.37 KB | 0755 |
|
| iptables-nft-save | File | 271.37 KB | 0755 |
|
| iptables-restore | File | 271.37 KB | 0755 |
|
| iptables-restore-translate | File | 271.37 KB | 0755 |
|
| iptables-save | File | 271.37 KB | 0755 |
|
| iptables-translate | File | 271.37 KB | 0755 |
|
| iptunnel | File | 18.38 KB | 0755 |
|
| isosize | File | 14.45 KB | 0755 |
|
| ispell-autobuildhash | File | 15.52 KB | 0755 |
|
| iucode-tool | File | 54.34 KB | 0755 |
|
| iucode_tool | File | 54.34 KB | 0755 |
|
| iw | File | 307.85 KB | 0755 |
|
| javacalls-bpfcc | File | 55 B | 0755 |
|
| javaflow-bpfcc | File | 54 B | 0755 |
|
| javagc-bpfcc | File | 52 B | 0755 |
|
| javaobjnew-bpfcc | File | 56 B | 0755 |
|
| javastat-bpfcc | File | 54 B | 0755 |
|
| javathreads-bpfcc | File | 57 B | 0755 |
|
| kbdrate | File | 18.38 KB | 0755 |
|
| kdump-config | File | 38.98 KB | 0755 |
|
| kexec | File | 190.41 KB | 0755 |
|
| kexec-load-kernel | File | 2.31 KB | 0755 |
|
| killall5 | File | 26.3 KB | 0755 |
|
| killsnoop-bpfcc | File | 4.45 KB | 0755 |
|
| killsnoop.bt | File | 873 B | 0755 |
|
| klockstat-bpfcc | File | 13.04 KB | 0755 |
|
| kvmexit-bpfcc | File | 11.19 KB | 0755 |
|
| ldattach | File | 26.45 KB | 0755 |
|
| ldconfig | File | 387 B | 0755 |
|
| ldconfig.real | File | 1.03 MB | 0755 |
|
| llcstat-bpfcc | File | 4.48 KB | 0755 |
|
| loads.bt | File | 1.1 KB | 0755 |
|
| locale-gen | File | 4.35 KB | 0755 |
|
| logrotate | File | 94.31 KB | 0755 |
|
| logsave | File | 18.23 KB | 0755 |
|
| losetup | File | 78.63 KB | 0755 |
|
| lpadmin | File | 34.38 KB | 0755 |
|
| lpc | File | 14.43 KB | 0755 |
|
| lpinfo | File | 14.38 KB | 0755 |
|
| lpmove | File | 14.38 KB | 0755 |
|
| lsmod | File | 194.31 KB | 0755 |
|
| lspcmcia | File | 22.59 KB | 0755 |
|
| make-ssl-cert | File | 6.65 KB | 0755 |
|
| mdflush-bpfcc | File | 2.24 KB | 0755 |
|
| mdflush.bt | File | 775 B | 0755 |
|
| memleak-bpfcc | File | 20.92 KB | 0755 |
|
| mii-tool | File | 26.81 KB | 0755 |
|
| mkdosfs | File | 54.9 KB | 0755 |
|
| mke2fs | File | 146.7 KB | 0755 |
|
| mkfs | File | 14.45 KB | 0755 |
|
| mkfs.btrfs | File | 852.66 KB | 0755 |
|
| mkfs.exfat | File | 30.46 KB | 0755 |
|
| mkfs.ext2 | File | 146.7 KB | 0755 |
|
| mkfs.ext3 | File | 146.7 KB | 0755 |
|
| mkfs.ext4 | File | 146.7 KB | 0755 |
|
| mkfs.fat | File | 54.9 KB | 0755 |
|
| mkfs.msdos | File | 54.9 KB | 0755 |
|
| mkfs.ntfs | File | 74.46 KB | 0755 |
|
| mkfs.vfat | File | 54.9 KB | 0755 |
|
| mkhomedir_helper | File | 22.41 KB | 0755 |
|
| mkinitramfs | File | 15.5 KB | 0755 |
|
| mklost+found | File | 14.38 KB | 0755 |
|
| mkntfs | File | 74.46 KB | 0755 |
|
| mkswap | File | 54.46 KB | 0755 |
|
| modinfo | File | 194.31 KB | 0755 |
|
| modprobe | File | 194.31 KB | 0755 |
|
| mount.fuse | File | 18.38 KB | 0755 |
|
| mount.fuse3 | File | 18.38 KB | 0755 |
|
| mount.lowntfs-3g | File | 131.05 KB | 0755 |
|
| mount.ntfs | File | 175.09 KB | 4755 |
|
| mount.ntfs-3g | File | 175.09 KB | 4755 |
|
| mountsnoop-bpfcc | File | 14.62 KB | 0755 |
|
| mysqld | File | 59.28 MB | 0755 |
|
| mysqld_qslower-bpfcc | File | 3.05 KB | 0755 |
|
| nameif | File | 14.47 KB | 0755 |
|
| naptime.bt | File | 1.01 KB | 0755 |
|
| netplan | File | 802 B | 0755 |
|
| netqtop-bpfcc | File | 5.59 KB | 0755 |
|
| newusers | File | 83.04 KB | 0755 |
|
| nfnl_osf | File | 18.38 KB | 0755 |
|
| nfsdist-bpfcc | File | 4.95 KB | 0755 |
|
| nfsslower-bpfcc | File | 13.61 KB | 0755 |
|
| nft | File | 26.3 KB | 0755 |
|
| nodegc-bpfcc | File | 52 B | 0755 |
|
| nodestat-bpfcc | File | 54 B | 0755 |
|
| nologin | File | 14.45 KB | 0755 |
|
| ntfsclone | File | 50.46 KB | 0755 |
|
| ntfscp | File | 34.45 KB | 0755 |
|
| ntfslabel | File | 22.45 KB | 0755 |
|
| ntfsresize | File | 66.47 KB | 0755 |
|
| ntfsundelete | File | 50.46 KB | 0755 |
|
| offcputime-bpfcc | File | 13.46 KB | 0755 |
|
| offwaketime-bpfcc | File | 15.31 KB | 0755 |
|
| on_ac_power | File | 2.45 KB | 0755 |
|
| oomkill-bpfcc | File | 2.04 KB | 0755 |
|
| oomkill.bt | File | 1.17 KB | 0755 |
|
| opensnoop-bpfcc | File | 14.24 KB | 0755 |
|
| opensnoop.bt | File | 953 B | 0755 |
|
| openvpn | File | 1.04 MB | 0755 |
|
| ownership | File | 14.52 KB | 0755 |
|
| pam-auth-update | File | 20.96 KB | 0755 |
|
| pam_extrausers_chkpwd | File | 30.38 KB | 2755 |
|
| pam_extrausers_update | File | 34.39 KB | 0755 |
|
| pam_getenv | File | 2.82 KB | 0755 |
|
| pam_namespace_helper | File | 467 B | 0755 |
|
| pam_timestamp_check | File | 14.38 KB | 0755 |
|
| paperconfig | File | 3.55 KB | 0755 |
|
| parted | File | 122.48 KB | 0755 |
|
| partprobe | File | 14.45 KB | 0755 |
|
| pccardctl | File | 22.59 KB | 0755 |
|
| perlcalls-bpfcc | File | 55 B | 0755 |
|
| perlflow-bpfcc | File | 54 B | 0755 |
|
| perlstat-bpfcc | File | 54 B | 0755 |
|
| phpcalls-bpfcc | File | 54 B | 0755 |
|
| phpdismod | File | 7.11 KB | 0755 |
|
| phpenmod | File | 7.11 KB | 0755 |
|
| phpflow-bpfcc | File | 53 B | 0755 |
|
| phpquery | File | 6.24 KB | 0755 |
|
| phpstat-bpfcc | File | 53 B | 0755 |
|
| pidpersec-bpfcc | File | 1.08 KB | 0755 |
|
| pidpersec.bt | File | 628 B | 0755 |
|
| pivot_root | File | 14.45 KB | 0755 |
|
| plipconfig | File | 14.38 KB | 0755 |
|
| plymouthd | File | 150.65 KB | 0755 |
|
| poweroff | File | 299 KB | 0755 |
|
| ppchcalls-bpfcc | File | 13.89 KB | 0755 |
|
| pppd | File | 494.71 KB | 4754 |
|
| pppdump | File | 18.38 KB | 0755 |
|
| pppoe-discovery | File | 30.37 KB | 0755 |
|
| pppstats | File | 18.37 KB | 0755 |
|
| pptp | File | 67.16 KB | 0755 |
|
| pptpsetup | File | 6.49 KB | 0755 |
|
| profile-bpfcc | File | 14.41 KB | 0755 |
|
| pwck | File | 58.45 KB | 0755 |
|
| pwconv | File | 50.32 KB | 0755 |
|
| pwhistory_helper | File | 22.38 KB | 0755 |
|
| pwunconv | File | 46.32 KB | 0755 |
|
| pythoncalls-bpfcc | File | 57 B | 0755 |
|
| pythonflow-bpfcc | File | 56 B | 0755 |
|
| pythongc-bpfcc | File | 54 B | 0755 |
|
| pythonstat-bpfcc | File | 56 B | 0755 |
|
| rarp | File | 36.41 KB | 0755 |
|
| rdmaucma-bpfcc | File | 4.95 KB | 0755 |
|
| readahead-bpfcc | File | 6.54 KB | 0755 |
|
| readprofile | File | 22.48 KB | 0755 |
|
| reboot | File | 299 KB | 0755 |
|
| remove-default-ispell | File | 2.86 KB | 0755 |
|
| remove-default-wordlist | File | 2.86 KB | 0755 |
|
| remove-shell | File | 1.08 KB | 0755 |
|
| reset-trace-bpfcc | File | 3.42 KB | 0755 |
|
| resize2fs | File | 70.38 KB | 0755 |
|
| resolvconf | File | 178.69 KB | 0755 |
|
| rfkill | File | 30.3 KB | 0755 |
|
| rmmod | File | 194.31 KB | 0755 |
|
| rmt | File | 62.76 KB | 0755 |
|
| rmt-tar | File | 62.76 KB | 0755 |
|
| route | File | 76.34 KB | 0755 |
|
| rsyslogd | File | 852.39 KB | 0755 |
|
| rtacct | File | 28.39 KB | 0755 |
|
| rtcwake | File | 34.45 KB | 0755 |
|
| rtkitctl | File | 14.38 KB | 0755 |
|
| rtmon | File | 134.59 KB | 0755 |
|
| rubycalls-bpfcc | File | 55 B | 0755 |
|
| rubyflow-bpfcc | File | 54 B | 0755 |
|
| rubygc-bpfcc | File | 52 B | 0755 |
|
| rubyobjnew-bpfcc | File | 56 B | 0755 |
|
| rubystat-bpfcc | File | 54 B | 0755 |
|
| runlevel | File | 299 KB | 0755 |
|
| runqlat-bpfcc | File | 9.3 KB | 0755 |
|
| runqlat.bt | File | 788 B | 0755 |
|
| runqlen-bpfcc | File | 8.05 KB | 0755 |
|
| runqlen.bt | File | 1.01 KB | 0755 |
|
| runqslower-bpfcc | File | 9.01 KB | 0755 |
|
| runuser | File | 54.45 KB | 0755 |
|
| saned | File | 82.88 KB | 0755 |
|
| select-default-ispell | File | 3.23 KB | 0755 |
|
| select-default-wordlist | File | 3.21 KB | 0755 |
|
| service | File | 8.99 KB | 0755 |
|
| setcap | File | 14.38 KB | 0755 |
|
| setuids.bt | File | 1.76 KB | 0755 |
|
| setvesablank | File | 14.45 KB | 0755 |
|
| setvtrgb | File | 14.51 KB | 0755 |
|
| sfdisk | File | 106.45 KB | 0755 |
|
| sgdisk | File | 178.56 KB | 0755 |
|
| shadowconfig | File | 2.22 KB | 0755 |
|
| shmsnoop-bpfcc | File | 7.8 KB | 0755 |
|
| shutdown | File | 299 KB | 0755 |
|
| slabratetop-bpfcc | File | 6.66 KB | 0755 |
|
| slattach | File | 40.16 KB | 0755 |
|
| sofdsnoop-bpfcc | File | 8.06 KB | 0755 |
|
| softirqs-bpfcc | File | 5.59 KB | 0755 |
|
| solisten-bpfcc | File | 5.96 KB | 0755 |
|
| spice-vdagentd | File | 58.9 KB | 0755 |
|
| split-logfile | File | 2.36 KB | 0755 |
|
| sshd | File | 458.96 KB | 0755 |
|
| ssllatency.bt | File | 2.12 KB | 0755 |
|
| sslsniff-bpfcc | File | 13.68 KB | 0755 |
|
| sslsnoop.bt | File | 2.03 KB | 0755 |
|
| sssd | File | 54.45 KB | 0755 |
|
| stackcount-bpfcc | File | 16.26 KB | 0755 |
|
| start-stop-daemon | File | 47.57 KB | 0755 |
|
| statsnoop-bpfcc | File | 4.92 KB | 0755 |
|
| statsnoop.bt | File | 1.26 KB | 0755 |
|
| sudo_logsrvd | File | 256.58 KB | 0755 |
|
| sudo_sendlog | File | 135.75 KB | 0755 |
|
| sulogin | File | 42.46 KB | 0755 |
|
| swapin.bt | File | 946 B | 0755 |
|
| swaplabel | File | 18.45 KB | 0755 |
|
| swapoff | File | 22.45 KB | 0755 |
|
| swapon | File | 46.45 KB | 0755 |
|
| switch_root | File | 22.45 KB | 0755 |
|
| syncsnoop-bpfcc | File | 1.27 KB | 0755 |
|
| syncsnoop.bt | File | 839 B | 0755 |
|
| syscount-bpfcc | File | 8.57 KB | 0755 |
|
| syscount.bt | File | 872 B | 0755 |
|
| sysctl | File | 30.46 KB | 0755 |
|
| tarcat | File | 936 B | 0755 |
|
| tc | File | 743.73 KB | 0755 |
|
| tclcalls-bpfcc | File | 54 B | 0755 |
|
| tclflow-bpfcc | File | 53 B | 0755 |
|
| tclobjnew-bpfcc | File | 55 B | 0755 |
|
| tclstat-bpfcc | File | 53 B | 0755 |
|
| tcpaccept-bpfcc | File | 9 KB | 0755 |
|
| tcpaccept.bt | File | 1.93 KB | 0755 |
|
| tcpcong-bpfcc | File | 20.11 KB | 0755 |
|
| tcpconnect-bpfcc | File | 18.46 KB | 0755 |
|
| tcpconnect.bt | File | 1.83 KB | 0755 |
|
| tcpconnlat-bpfcc | File | 9.07 KB | 0755 |
|
| tcpdrop-bpfcc | File | 8.1 KB | 0755 |
|
| tcpdrop.bt | File | 2.63 KB | 0755 |
|
| tcplife-bpfcc | File | 16.55 KB | 0755 |
|
| tcplife.bt | File | 2.93 KB | 0755 |
|
| tcpretrans-bpfcc | File | 13.77 KB | 0755 |
|
| tcpretrans.bt | File | 2.29 KB | 0755 |
|
| tcprtt-bpfcc | File | 8.7 KB | 0755 |
|
| tcpstates-bpfcc | File | 13.73 KB | 0755 |
|
| tcpsubnet-bpfcc | File | 7.63 KB | 0755 |
|
| tcpsynbl-bpfcc | File | 2.12 KB | 0755 |
|
| tcpsynbl.bt | File | 962 B | 0755 |
|
| tcptop-bpfcc | File | 12.64 KB | 0755 |
|
| tcptracer-bpfcc | File | 17.71 KB | 0755 |
|
| telinit | File | 299 KB | 0755 |
|
| thermald | File | 534.81 KB | 0755 |
|
| threadsnoop-bpfcc | File | 1.81 KB | 0755 |
|
| threadsnoop.bt | File | 752 B | 0755 |
|
| tipc | File | 98.59 KB | 0755 |
|
| tplist-bpfcc | File | 4.06 KB | 0755 |
|
| trace-bpfcc | File | 42.86 KB | 0755 |
|
| ttysnoop-bpfcc | File | 7.59 KB | 0755 |
|
| tune.exfat | File | 38.73 KB | 0755 |
|
| tune2fs | File | 114.64 KB | 0755 |
|
| u-d-c-print-pci-ids | File | 517 B | 0755 |
|
| ucalls | File | 11.69 KB | 0755 |
|
| uflow | File | 7.92 KB | 0755 |
|
| ufw | File | 4.84 KB | 0755 |
|
| ugc | File | 7.64 KB | 0755 |
|
| umount.udisks2 | File | 14.38 KB | 0755 |
|
| undump.bt | File | 789 B | 0755 |
|
| unix_chkpwd | File | 30.38 KB | 2755 |
|
| unix_update | File | 34.38 KB | 0755 |
|
| uobjnew | File | 6.04 KB | 0755 |
|
| update-ca-certificates | File | 5.32 KB | 0755 |
|
| update-catalog | File | 9.17 KB | 0755 |
|
| update-cracklib | File | 1.15 KB | 0755 |
|
| update-default-aspell | File | 1 KB | 0755 |
|
| update-default-ispell | File | 9.68 KB | 0755 |
|
| update-default-wordlist | File | 7.5 KB | 0755 |
|
| update-dictcommon-aspell | File | 1 KB | 0755 |
|
| update-dictcommon-hunspell | File | 782 B | 0755 |
|
| update-fonts-alias | File | 5.71 KB | 0755 |
|
| update-fonts-dir | File | 3.98 KB | 0755 |
|
| update-fonts-scale | File | 6.1 KB | 0755 |
|
| update-grub | File | 64 B | 0755 |
|
| update-grub2 | File | 64 B | 0755 |
|
| update-gsfontmap | File | 390 B | 0755 |
|
| update-icon-caches | File | 596 B | 0755 |
|
| update-ieee-data | File | 3.41 KB | 0755 |
|
| update-inetd | File | 5.83 KB | 0755 |
|
| update-info-dir | File | 1.66 KB | 0755 |
|
| update-initramfs | File | 7.57 KB | 0755 |
|
| update-locale | File | 3.02 KB | 0755 |
|
| update-passwd | File | 34.64 KB | 0755 |
|
| update-pciids | File | 2.12 KB | 0755 |
|
| update-rc.d | File | 17.72 KB | 0755 |
|
| update-secureboot-policy | File | 7.43 KB | 0755 |
|
| update-shells | File | 3.97 KB | 0755 |
|
| update-xmlcatalog | File | 16.88 KB | 0755 |
|
| usb_modeswitch | File | 59.74 KB | 0755 |
|
| usb_modeswitch_dispatcher | File | 26.78 KB | 0755 |
|
| usbmuxd | File | 94.75 KB | 0755 |
|
| useradd | File | 144.01 KB | 0755 |
|
| userdel | File | 91.16 KB | 0755 |
|
| usermod | File | 131.82 KB | 0755 |
|
| ustat | File | 12.12 KB | 0755 |
|
| uthreads | File | 4 KB | 0755 |
|
| uuidd | File | 30.95 KB | 0755 |
|
| validlocale | File | 1.73 KB | 0755 |
|
| vcstime | File | 14.37 KB | 0755 |
|
| vdpa | File | 38.64 KB | 0755 |
|
| vfscount-bpfcc | File | 1.36 KB | 0755 |
|
| vfscount.bt | File | 515 B | 0755 |
|
| vfsstat-bpfcc | File | 4.06 KB | 0755 |
|
| vfsstat.bt | File | 721 B | 0755 |
|
| vigr | File | 60.82 KB | 0755 |
|
| vipw | File | 60.82 KB | 0755 |
|
| virtiostat-bpfcc | File | 8.69 KB | 0755 |
|
| visudo | File | 260.95 KB | 0755 |
|
| vmcore-dmesg | File | 30.25 KB | 0755 |
|
| vpddecode | File | 14.66 KB | 0755 |
|
| vsftpd | File | 176.54 KB | 0755 |
|
| wakeuptime-bpfcc | File | 8.1 KB | 0755 |
|
| wipefs | File | 38.45 KB | 0755 |
|
| wpa_action | File | 1.69 KB | 0755 |
|
| wpa_cli | File | 148.39 KB | 0755 |
|
| wpa_supplicant | File | 3.96 MB | 0755 |
|
| wqlat-bpfcc | File | 4.95 KB | 0755 |
|
| writeback.bt | File | 1.66 KB | 0755 |
|
| xfsdist-bpfcc | File | 4.61 KB | 0755 |
|
| xfsdist.bt | File | 1012 B | 0755 |
|
| xfsslower-bpfcc | File | 7.78 KB | 0755 |
|
| xtables-legacy-multi | File | 105.02 KB | 0755 |
|
| xtables-monitor | File | 271.37 KB | 0755 |
|
| xtables-nft-multi | File | 271.37 KB | 0755 |
|
| zfsdist-bpfcc | File | 5.3 KB | 0755 |
|
| zfsslower-bpfcc | File | 8.45 KB | 0755 |
|
| zic | File | 66.47 KB | 0755 |
|
| zramctl | File | 58.59 KB | 0755 |
|