The InfoQ Podcast · 2026-06-22 · 44 min
Daniel Finneran explores how eBPF has evolved far beyond its roots in packet filtering into a robust, safe way to extend the Linux kernel. He explains how the eBPF "verifier", the security guardrail, enables implementation of deep observability and networking without the risks of traditional kernel modules or the slow upstreaming process. He touches on tools like Tetragon that leverage eBPF for "front-foot" security enforcement, proactively intercepting threats such as buffer overflows before they execute, while providing visibility into file systems and drivers without intrusive instrumentation. Read a transcript of this interview: Newsletter: