Process and syscall awareness made efficient
Collect only the syscalls, namespaces, and process states that map to declared policies and real attack paths. Bloom filters, ring buffers, and eBPF tail calls keep footprints tiny. Focus on invariants, not exhaustive logs, so detections stay sharp, memory predictable, and engineering energy funnels into prevention instead of endless after-the-fact searches.