We want to enable (truly) free and open source threat intelligence for the cloud native ecosystem and create an OpenSource Kubernetes SOC
What started with honeyclusters, became a project to instrument kubernetes for live adaptive detection, meaning to construct an algorithm of detection mechanisms to auto-tune the finding of interesting activity on a large and distributed system.
It should be noted, that a large usecase is to "simulate" the attack by using synthetic attacks (attack yourself) to test if a team can a) detect and b) defend and c) incident respond (as required by e.g. NIS-2). You will find the majority of the functionality in:
- bob : how to tune your runtime-behavior config
- node-agent : how to sign and detect using individual events
- pixie: how to have multi-cluster visibility The magic lies in cross-correlating the three.
Contributions, ideas and discussions from the cloud-native community are very welcome. We encourage users to report any issues. Sample livelabs may be found on the iximiuz-labs platform.
There is a SLACK for the community [https://join.slack.com/t/k8sstorm/signup]
This is a not-for-profit community project (with absolutely no liability).
