__ __ __ __ _____ _ _ _____ _ _ _ | \/ | \ \ / / | __ \ (_) | | / ____| | | | | | \ / |_ __\ V / | |__) | __ ___ ____ _| |_ ___ | (___ | |__ ___| | | | |\/| | '__|> < | ___/ '__| \ \ / / _` | __/ _ \ \___ \| '_ \ / _ \ | | | | | | |_ / . \ | | | | | |\ V / (_| | || __/ ____) | | | | __/ | | |_| |_|_(_)_/ \_\ |_| |_| |_| \_/ \__,_|\__\___| |_____/|_| |_|\___V 2.1 if you need WebShell for Seo everyday contact me on Telegram Telegram Address : @jackleetFor_More_Tools:
Demonstrations of filegone, the Linux eBPF/bcc version.
filegone traces why file gone, either been deleted or renamed
For example:
# ./filegone
18:30:56 22905 vim DELETE .fstab.swpx
18:30:56 22905 vim DELETE .fstab.swp
18:31:00 22905 vim DELETE .viminfo
18:31:00 22905 vim RENAME .viminfo.tmp > .viminfo
18:31:00 22905 vim DELETE .fstab.swp
USAGE message:
usage: filegone.py [-h] [-p PID]
Trace why file gone (deleted or renamed)
optional arguments:
-h, --help show this help message and exit
-p PID, --pid PID trace this PID only
examples:
./filegone # trace all file gone events
./filegone -p 181 # only trace PID 181