Session
How Clusters Fail Under Attack and How We Detect It at Runtime with eBPF signals
Most Kubernetes security work today happens before deployment. Teams scan images and secure their pipelines, but incidents usually happen after the container is already running. If someone gets access to a pod, many traditional tools provide very little visibility into what the workload actually does on the node.
In this session I introduce runtime security with eBPF, a Linux kernel capability that lets us observe system behavior in real time without modifying applications or containers. We will look at how real attacks appear in Kubernetes environments such as reverse shells, privilege escalation attempts, and unexpected process execution.
Using practical examples and open source tools, I will demonstrate how these activities can be detected and investigated, and how runtime detection complements preventive security controls. The goal is to give attendees a clear mental model of runtime threats and a practical starting point for adding detection to their production clusters.
Mohamed Ali Mellah
Cloud-Native & Kubernetes Engineer
Munich, Germany
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top