KubeCon + CloudNativeCon Europe

Tutorial: Attack Defense: Leverage eBPF To Reveal Attack Flows... Constanze R, Markus G & Teodor P

1:23:07 · 23 Mar 2026 – 26 Mar 2026 · YouTube

About this talk

This tutorial, presented by Constanze Roedig from fusioncore.ai, Markus Gierlinger, and Teodor Janez Podobnik from Prewave GmbH, focuses on leveraging eBPF to reveal attack flows with rich context. The speakers demonstrate how mature Free and Open Source Software (FOSS) eBPF tools can illuminate previously invisible activities by interacting with the kernel. Participants will learn about various attack techniques identified by the MITRE framework, such as intercepting malicious payloads in encrypted traffic, analyzing file access, and tracing pivots among services at both the user interface and kernel level. The session includes hands-on exercises using personal laptops to access a pre-configured lab environment, ensuring an interactive learning experience.