Figure 3: Coroot is based on eBPF, the successor to the Berkeley Packet Filter filtering mechanism in Linux, and is used in container environments to intercept network traffic for direct analysis at the Linux kernel level. © Coroot