Session

Lateral Movement Lockdown: Automated Threat Containment with Cilium, Tetragon, and Hubble

Lateral movement is the true cluster killer. We found that by the time our old security stack logged a successful exploit, the attacker had already moved laterally to sensitive secrets. This proved that traditional controls were simply too slow for cloud-native velocity.
This session shares the operational walkthrough for how we built a dynamic, self-healing security loop using Cilium and Tetragon. We moved enforcement into the kernel via eBPF to achieve near-instant containment.
What we share (and what we learned):
1. The Detection: How we instrumented Tetragon to detect specific, high-fidelity runtime anomalies (e.g., unauthorized shell execution or suspicious file access), and the challenges of managing false positives.
2. The Containment Loop: The logic for instantly translating a critical Tetragon event into a precise, identity-aware Cilium Network Policy to "shrink-wrap" the compromised workload.
3. Using Hubble to visualize the containment

Abhinav Sharma

Site Reliability Engineer at KodeKloud | Microsoft MVP | GSOC @OpenSUSE | GitHub Campus Expert

Jaipur, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top