Attack Graph rendered in CNCF Pixie
Visualising reconstructed attack trees
Cutting through the noise to help analysts find attacks faster (25.06.2026)
Förderjahr 2025 / Projekt Call #20 / ProjektID: 7918 / Projekt: Sovereign SOC

Time to detection matters in security and human analysts need tools to find the truth fast: This is why we added a new extension that helps analysts query the evidence not only programmatically but also visually

Alert fatigue is a real problem for human analysts. As shown below the real "signal" is usually buried in a lot of noise. This article shows how we now have both programmatical as well as visual means to find potential attacks. 

Noise

Many clusters - one central UI

A key reason, why we chose CNCF Pixie is its ability to manage a large number of clusters in one single interface. The clusters specify which 'group' they belong to when the local sensors (Pixie Edge Module "pem") first connect to the central cockpit instance. The configuration of the auth provider can be provisioned e.g. via Terraform and an example is available in the source code.

Once both analyst user and cluster(s) are authenticated to the same group, the analyst is able to query all data, whether still on the clusters (in-memory) or already stored in the forensic database (in Clickhouse). A user may chose to visualize the data from a scatch pad ad-hoc or by using the new built-in widget, that specifically allows edges to be coloured and labelled bespoke to the needs of a security analyst:

preconfigured security widget

We specifically want to point out the fact, that the data is never locally persisted in the UI, it is queried from the external database and rendered, and the feature-set that extends Pixie with this ability to both write and read from external Clickhouse Database, is a core component of this grant. All credit goes to the Pixie Team for their amazing collaboration.  

The new feature behind the scenes: the link to the database

The entire architecture of the sovereign SOC critically depends on having the ability to both read and write (safely) to the external database, as the records need to be protected from being altered if there really is an attacker in the system:

Highlevel schematic overview  

Tags:

eBPF digital sovereignty cybersecurity

Constanze Roedig

Profile picture for user constanze.roedig
Constanze is an astrophysicist turned entrepreneur: she spent over 15 years designing and implementing resilient complex systems for finance and government. CS lecturer and key researcher. Created the K8s Stormcenter for Open Threat Intelligence. Her research is on improving security using modern and emerging technologies such as eBPF, WebAssembly and AI. Her vision is to create practical and achievable security implementations usable in defendable systems for a resilient society.

Skills:

eBPF
CAPTCHA
Diese Frage dient der Überprüfung, ob Sie ein menschlicher Besucher sind und um automatisierten SPAM zu verhindern.