Linux kernel technology (Extended Berkeley Packet Filter) enabling safe, efficient instrumentation of kernel events. Guiney cites eBPF alongside cgroups as what allows observability at the kernel/network level without modifying applications — producing service maps and traces without instrumenting application code. Recommends asking operations teams about it.