From kernel panics to parent process deception — a practical account of building real-time container security tooling with eBPF.