# Syscalls tapped by elastic defend

**URL:** <https://discuss.elastic.co/t/syscalls-tapped-by-elastic-defend/378135>\
**Category:** Endpoint Security\
**Created:** [May 14, 2025, 12:08pm UTC](https://discuss.elastic.co/t/syscalls-tapped-by-elastic-defend/378135 "2025-05-14T12:08:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Snow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snow/32/139864_2.png) [@Snow](https://discuss.elastic.co/u/Snow)\
**Post date:** [May 14, 2025, 12:08pm UTC](https://discuss.elastic.co/t/syscalls-tapped-by-elastic-defend/378135/1 "2025-05-14T12:08:18Z")

</div>

i could see the below list of events tapped by elastic defend, apart from this, what are the list of syscalls tapped by elastic defend?

end (process event)  
fork (process event)  
exec (process event)  
uid\_change (process event)  
gid\_change (process event)  
session\_id\_change (process event)  
already\_running (process event)  
process-started (process event)  
session\_id\_change (process event)  
connection\_accepted (network event)  
connection\_attempted (network event)  
disconnect\_received (network event)  
creation (file event)  
rename (file event)  
deletion (file event)

---

<div class="post-metadata">

**Author:** ![Snow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snow/32/139864_2.png) [@Snow](https://discuss.elastic.co/u/Snow)\
**Post date:** [May 26, 2025, 10:16am UTC](https://discuss.elastic.co/t/syscalls-tapped-by-elastic-defend/378135/2 "2025-05-26T10:16:39Z")

</div>

@Christian_Dahlqvist / @stephenb could you pls help?

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [May 26, 2025, 11:17am UTC](https://discuss.elastic.co/t/syscalls-tapped-by-elastic-defend/378135/3 "2025-05-26T11:17:51Z")

</div>

> @Christian_Dahlqvist / @stephenb could you pls help?

Er, thats a bit rude, though at least you included a "pls".

Remember its public forum, anyone (volunteers) can choose to answer whichever threads they wish. Or not. There's no SLA here.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 26, 2025, 11:40am UTC](https://discuss.elastic.co/t/syscalls-tapped-by-elastic-defend/378135/4 "2025-05-26T11:40:38Z")

</div>

I find pinging specific people very rude and usually ignore people who do this completely. Will do so this time as well once I am done with this point. This is as @RainTown pointed out a community forum manned by volunteers and you do not know which areas different users have experience with. Have you ever seen me respond to any question around Elastic Defend? (The answer is no as I do not use this product.)

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [May 27, 2025, 7:58am UTC](https://discuss.elastic.co/t/syscalls-tapped-by-elastic-defend/378135/5 "2025-05-27T07:58:01Z")

</div>

For some reason discuss didn't send this to me before today.

Assuming you're running an ebpf enabled system, our ebpf probes are maintained in the elastic/ebpf repo. There's a list of the "events" we're creating here: [ebpf/GPL/Events/EbpfEventProto.h at main · elastic/ebpf · GitHub](https://github.com/elastic/ebpf/blob/main/GPL/Events/EbpfEventProto.h#L25)

Specific events and probe locations can vary over time and versions, but it is all built from that repo.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2025, 7:58am UTC](https://discuss.elastic.co/t/syscalls-tapped-by-elastic-defend/378135/6 "2025-06-24T07:58:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
