Sovereign SOC
Förderjahr 2025 / Projekt Call #20 / ProjectID: 7918
The linux kernel through eBPF offers to unify the disparate fields security and observability through shared data structures. This project prototypes a K8s Security Operations Center, organically composed of established eBPF projects (CNCF Kubescape, Pixie and Tetragon) which can see signals that the individuals cannot.
The SOC is based on a comprehensive baseline and uses independent signals to dial up/down coverage as suspicious indicators surface. The mutual independence of signals from across processes, file system, and network activity achieves a high signal-to-noise, enabling manageable data volumes and facilitating selective forensic storage.
Additionally, our SOC architecture is node-local, and no data leaves the cluster meaning you remain sovereign and in control of your data.