Design and operate eBPF-based runtime security on Linux hosts and Kubernetes — Falco, Tetragon, Tracee, Cilium NetworkPolicy / Hubble — for syscall-level threat detection, container-escape prevention, kernel-anchored process and network observability, and inline policy enforcement. Use when building runtime detection, evaluating CNAPP/CWPP tooling, hardening clusters against post-exploitation, or hunting kernel-level threats.