6 Live Labs Β· Zero Backend Β· eBPF + TypeSafe AI + K8s

🐧 eBPF Swarm Playground

Every concept from the capstone β€” syscall interception, Verifier safety, ring buffers, TypeSafe AI decisions, XDP firewalls, and K8s AutoSOC β€” running live in your browser. Pick scenarios, earn XP, earn badges.

Pure JS Β· No backend Β· No libraries
πŸ”΄ Ring 0 β†’ πŸ”΅ Ring 3 β†’ 🧠 TypeSafe β†’ ☸️ K8s
⚑ 6 Labs · 8 Quiz questions · 7 Badges
1
Syscall
2
Verifier
3
Ring Buffer
4
TypeSafe AI
5
XDP Firewall
6
K8s AutoSOC
πŸŽ“
Quiz
πŸ—ΊοΈ The Autonomous SIEM Pipeline β€” What You Are Building

Each lab corresponds to a real stage in our capstone. A reverse shell detected at Ring 0 becomes an autonomous cluster-wide quarantine in 400ms β€” zero human in the loop. Animate it below.

πŸ”΄
eBPF Hook
sys_enter_execve
Ring 0 Β· Kernel
β†’
πŸ”΅
Ring Buffer
BPF_PERF_OUTPUT
Zero-copy
β†’
🐍
Python Agent
Heuristic filter
Ring 3
β†’
🧠
TypeSafe AI
Noul Β· Choice
Deterministic
β†’
☸️
K8s Operator
NetworkPolicy
Quarantine
πŸ’‘
Key Insight
PID 442644 executing nc -e /bin/bash was detected and the pod isolated in under 400ms. No human in the loop. No hallucination possible.

πŸ”΄ Lab 1 β€” Syscall Interceptor Β· Ring 0 eBPF

πŸ”΄ Lab 1 β€” Syscall Scenario Simulator Ring 0

Pick a scenario. The eBPF tracepoint fires on sys_enter_execve and extracts PID/PPID from task_struct. Can you identify the real reverse shell vs false positives β€” like a Tier-2 SOC analyst would?

sys_enter_execve task_struct BPF_PERF_OUTPUT
πŸ‘† Select a scenario β†’ read the eBPF telemetry β†’ make your call
πŸ’»Reverse Shellnc -e /bin/bash
PID: 442644
πŸ–₯️GNOME Terminalvte-urlencode-cwd
Harmless?
πŸ”‘SSH Loginsshd β†’ bash
Lateral move?
πŸ•ΈοΈWeb Shellapache β†’ bash β†’ nc
Critical!
βš™οΈCron Jobcron β†’ /usr/bin/nc
Scheduled?
πŸ§ͺScannernmap β†’ nc
Pen test?
🎯
Challenge
"GNOME Terminal" matches the 'nc' substring β€” our naive detector flagged it as a THREAT. This is the real false positive from Test 1. TypeSafe AI (Lab 4) fixes it by evaluating the full parent chain, not just the filename.

πŸ›‘οΈ Lab 2 β€” eBPF Verifier Β· Mathematical Safety

πŸ’£ Lab 2A β€” Inject a Bomb dangerous

Try to slip malicious code past the Verifier. It statically proves all execution paths before a single instruction runs. No sampling. No fuzzing. Mathematical certainty.

Clang JIT BPF Verifier
πŸ‘† Select injection type β€” watch the Verifier pipeline respond
🎯
Challenge
Select "bigloop" β†’ Verifier rejects at 1M instruction limit. Same loop as a .ko module = kernel panic. This is why eBPF replaced kernel modules at Meta & Cloudflare.
βš”οΈ Lab 2B β€” .ko Module vs eBPF comparison

Same malicious code, two runtimes. See exactly why eBPF is safe and kernel modules are not.

πŸ‘† Select attack β€” see both outcomes side-by-side
πŸ’€ .ko Kernel Module
πŸ›‘οΈ eBPF Program
πŸ’‘
The Math
eBPF Verifier models every execution path and proves termination. Deployed by Meta, Cloudflare, and Google in production kernels.

πŸ”΅ Lab 3 β€” BPF Ring Buffer Β· Zero-Copy Data Path

πŸ”΅ Lab 3 β€” Ring Buffer Live Visualizer zero-copy

Visualize BPF_PERF_OUTPUT streaming kernel events to user-space asynchronously. Overwhelm the buffer to watch events drop β€” exactly what happens during a DDoS if your detector polls too slowly.

BPF_PERF_OUTPUT perf_buffer.poll()
πŸ‘† Increase event rate to simulate a DDoS β€” watch drops turn red
🎯
Challenge
Set rate=100, buffer=8, poll=500ms β†’ drops appear in red. This is why detector.py polls at 100ms. Set rate=5, buffer=64 β†’ zero drops. This balance determines real-world fidelity.

🧠 Lab 4 β€” TypeSafe AI Decision Engine

🎰 Lab 4A β€” Slot Machine vs ChatGPT deterministic

TypeSafe Choice always returns one of three hard-coded enums. ChatGPT returns free text β€” which breaks autonomous pipelines. Feed telemetry and compare both outputs.

Noul primitive Choice primitive
πŸ‘† Change process + parent β€” watch typed vs free-text respond
🧠 TypeSafe (typed)
πŸ’¬ Generic LLM (free text)
🎯
Challenge
nc + apache2 β†’ KILL_PROCESS at 97%. vte-urlencode-cwd + gnome-terminal β†’ IGNORE. Same binary, entirely different context. String matching cannot do this.
πŸ“Š Lab 4B β€” Noul Signal Composer live

TypeSafe Noul must return float 0.0–1.0. Toggle threat signals to build the composite probability. Cross the threshold β€” trigger the action automatically.

πŸ‘† Toggle signals β†’ watch probability compose in real time
0.0 β€” IGNORE0.6 β€” ALERT0.8 β€” QUARANTINE1.0 β€” KILL
πŸ’‘
Enterprise Insight
Multi-signal composition is exactly how SIEM correlation rules work β€” but TypeSafe makes the probability a typed, auditable float that code can act on directly, not a human's gut feeling.

πŸ”₯ Lab 5 β€” XDP Firewall Β· Hardware-Speed DDoS Defense

πŸ”₯ Lab 5 β€” XDP CPU Gauge Simulator hardware speed

Simulate a DDoS attack. Traditional iptables processes packets deep inside the kernel. XDP drops them at NIC level before sk_buff allocation. See the CPU delta β€” this is the Cloudflare model at Terabit scale.

XDP_DROP XDP_PASS iptables
πŸ‘† Ramp up attack β€” iptables CPU spikes, XDP stays flat
🎯
Challenge
5M PPS + iptables β†’ CPU 94% β†’ unresponsive. 5M PPS + XDP β†’ CPU 3% β†’ fully operational. This delta is why Cloudflare absorbs Terabit DDoS attacks without breaking a sweat.

☸️ Lab 6 β€” Kubernetes AutoSOC Operator

☸️ Lab 6 β€” AutoSOC Cluster Simulator self-healing

Simulate a live Kubernetes cluster of 12 pods. Inject a reverse shell. Watch the Go Operator detect the label security=compromised and isolate the pod with a NetworkPolicy β€” the immune system in action.

Reconciler Loop TypeSafe KILL NetworkPolicy
πŸ‘† Click a pod to compromise it manually, or use the action buttons
πŸ”΄
eBPF Detects
sys_enter_execve
β†’
🧠
TypeSafe KILL
Noul=0.95
β†’
🏷️
Label Pod
security=compromised
β†’
☸️
Reconciler
NetworkPolicy
β†’
πŸ”’
Isolated
400ms total
πŸ’‘
Self-Healing Infrastructure
The analyst reviews this on Monday morning. The cluster protected itself at 3am Friday. That's the difference between a $2M SIEM contract and a Go operator on a $50/month node.

πŸŽ“ SOC Engineer Quiz Β· Test Your Knowledge

πŸŽ“ SOC Quiz earn XP

8 questions modeled on real SOC Tier-2 analyst and SRE interview questions. Each correct answer = 25 XP.