SECURITY ENGINEERING · SYSTEMS RESEARCHNOTES FROM THE INSTRUMENTATION LAYER

Lead research log

ARTICLE · RESEARCH

Using eBPF as Behavioural Ground Truth for Threat Research and Detection Engineering

A container-scoped eBPF sensor for observing malware behaviour, probing telemetry coverage, and automating detection validation.

INTERMEDIATEEBPF · BCC · PYTHON
READ THE INVESTIGATION
SIGNAL PATHSOURCECOLLECTNORMALIZEDETECTANALYZE

Indexed collection

Recent research

Investigations, implementation notes and observations from detection engineering work.

VIEW THE COMPLETE RESEARCH INDEX →