eBPF sensors for real-world threat hunting

Anyone running eBPF-based sensors (e.g., Tetragon or Falco) in production to catch living-off-the-land and fileless behaviors? I’ve been testing Tetragon side-by-side with Falco on Ubuntu 22.04 and saw about 3–5% overhead during a 24-hour run; curious how they hold up under noisy workloads and whether you’re piping events into Sigma-ized detections or something else?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍‍‍​⁠‍​‌‌​​‌⁠‌‍​⁠​⁠‌⁠​⁠‌‌‌‍‌​⁠​‌⁠‍‍‌‌‍‌‌⁠​‍‌‍‍⁠‌​​‌‌​⁠‍​⁠‌‌‌‍​‌​‍​‍‌⁠⁠‌​