eBPF
Also written as Extended BPF, Cilium
A Linux technology that lets engineers run small, safe programs inside the operating system itself to watch or control network traffic, security events and performance, without changing application code. Cilium (Kubernetes networking) and many modern monitoring and security tools are built on it.
Think of it like
Fitting sensors inside the building's walls instead of asking every tenant to report what they see.
Junior or senior?
Using a tool built on eBPF is common; writing eBPF programs is rare and strongly differentiating.
Senior sounds like
Has written or debugged eBPF code and can talk about kernel-version limits.
Ask them
“Did you write eBPF programs yourself or use tools built on it? What did it show you that normal monitoring couldn't?”