In fact, GoDaddy has already written one, but it is not easy to use. It integrates Yara rules and the whitelist seems to be ineffective. https://github.com/godaddy/procfilter Looking forward to your progress