Zero Trust eBPF Kernel Observability & Hardening Lab
ENVIRONMENT: Ubuntu 24.04 LTS Kernel 6.8 Bare Metal Testbed
VISIBILITY: Public
TOOLS:
Tetragon
BCC Tools
Auditd
Sysdig
bpftrace
01 // Objective
Detect evasive rootkits, in-memory execution, and unauthorized kernel syscalls using real-time eBPF runtime observability.
02 // Methodology & Execution Steps
1. Simulated fileless reverse shell injection and credential dumping in memory.
2. Attached eBPF probes to syscall events (`execve`, `ptrace`, socket connections).
3. Evaluated automated kernel-space enforcement killing malicious processes in under 5ms.
03 // Findings & Attack Vector Verification
Traditional userspace monitoring produces significant overhead and can be blinded by rootkits. eBPF provides sub-millisecond, unbypassable enforcement directly inside the kernel.
04 // Remediation & Layered Defense
Deploy production eBPF runtime security engines (Tetragon/Falco) and enforce restricted kernel pointer inspection (`kptr_restrict=2`).
05 // Lessons Learned & Engineering Takeaways
Modern attackers bypass traditional file-integrity monitoring; defense must operate natively at the kernel syscall boundary.