+- Starting this version, Microsoft defender for Endpoint for Linux will no longer support AuditD as a supplementary event provider. For improved stability and performance, we have completely transitioned to eBPF. If you disable eBPF or in the event eBPF is not supported on any specific kernel, microsoft defender for endpoint for Linux will automatically switch back to Netlink as a fallback supplementary event provider. Netlink will provide reduced functionality and track only process related events. In this case, all process operations will continue to flow seamlessly, but you may miss out on specific file and socket-related events that eBPF would otherwise capture. For more details refer- [linux-support-ebpf.md](linux-support-ebpf.md). If you have any concerns or need assistance during this transition, contact support.
0 commit comments