Welcome to the Kubernetes Storm Center š Let's take the fear out of threats (by understanding them)
We want to enable (truly) free and open source threat intelligence for the cloud native ecosystem and create an OpenSource Kubernetes SOC
What started with honeyclusters, became a project to instrument kubernetes for live adaptive detection, meaning to construct an algorithm of detection mechanisms to auto-tune the finding of interesting activity on a large and distributed system.
It should be noted, that a large usecase is to "simulate" the attack by using synthetic attacks (attack yourself) to test if a team can a) detect and b) defend and c) incident respond (as required by e.g. NIS-2). You will find the majority of the functionality in:
- bob : how to tune your runtime-behavior config
- node-agent : how to sign and detect using individual events
- pixie: how to have multi-cluster visibility The magic lies in cross-correlating the three.
Contributions, ideas and discussions from the cloud-native community are very welcome. We encourage users to report any issues. Sample livelabs may be found on the iximiuz-labs platform.
There is a SLACK for the community [https://join.slack.com/t/k8sstorm/signup]
This is a not-for-profit community project (with absolutely no liability).
