File: //opt/sentinelone/mount/tracing/events/kprobes/s1execve_enter/format
name: s1execve_enter
ID: 1041
format:
field:unsigned short common_type; offset:0; size:2; signed:0;
field:unsigned char common_flags; offset:2; size:1; signed:0;
field:unsigned char common_preempt_count; offset:3; size:1; signed:0;
field:int common_pid; offset:4; size:4; signed:1;
field:int common_lock_depth; offset:8; size:4; signed:1;
field:unsigned long __probe_ip; offset:16; size:8; signed:0;
field:__data_loc char[] filename; offset:24; size:4; signed:1;
field:__data_loc char[] arg0; offset:28; size:4; signed:1;
field:__data_loc char[] arg1; offset:32; size:4; signed:1;
field:__data_loc char[] arg2; offset:36; size:4; signed:1;
field:__data_loc char[] arg3; offset:40; size:4; signed:1;
field:__data_loc char[] arg4; offset:44; size:4; signed:1;
field:__data_loc char[] arg5; offset:48; size:4; signed:1;
field:__data_loc char[] arg6; offset:52; size:4; signed:1;
field:__data_loc char[] arg7; offset:56; size:4; signed:1;
field:__data_loc char[] arg8; offset:60; size:4; signed:1;
field:__data_loc char[] arg9; offset:64; size:4; signed:1;
field:__data_loc char[] arg10; offset:68; size:4; signed:1;
field:__data_loc char[] arg11; offset:72; size:4; signed:1;
print fmt: "(%lx) filename=%lx arg0=%lx arg1=%lx arg2=%lx arg3=%lx arg4=%lx arg5=%lx arg6=%lx arg7=%lx arg8=%lx arg9=%lx arg10=%lx arg11=%lx", REC->__probe_ip, REC->filename, REC->arg0, REC->arg1, REC->arg2, REC->arg3, REC->arg4, REC->arg5, REC->arg6, REC->arg7, REC->arg8, REC->arg9, REC->arg10, REC->arg11