Detection and Blocking with BPF via YAML
Offered By: 44CON Information Security Conference via YouTube
Course Description
Overview
Explore the power of BPF (Berkeley Packet Filter) for detection and blocking through YAML configuration in this 47-minute conference talk from 44CON Information Security Conference. Learn how to leverage OSS Tetragon, a mature open-source BPF engine, to monitor and block actions without writing any BPF code. Discover techniques for hooking kernel functions, blocking actions, and killing processes using simple YAML configurations. Gain insights into sending events to logs, email, SMS, and Slack channels for comprehensive monitoring. Presented by Kev Sheldrake, a seasoned security software developer and researcher, this talk offers practical knowledge for implementing advanced security measures using BPF and YAML.
Syllabus
Kev Sheldrake - Detection and Blocking with BPF via YAML
Taught by
44CON Information Security Conference
Related Courses
Supply Chain Unchained - How To Be A Bad SaaS44CON Information Security Conference via YouTube Aviation Security 101
44CON Information Security Conference via YouTube The Anti-Checklist Manifesto
44CON Information Security Conference via YouTube Why Are We Still Doing Authentication Wrong?
44CON Information Security Conference via YouTube What Do Hackers See When They Look at the Clouds
44CON Information Security Conference via YouTube