6 Live Labs Β· Zero Backend Β· eBPF + TypeSafe AI + K8s
π§ eBPF Swarm Playground
Every concept from the capstone β syscall interception, Verifier safety, ring buffers, TypeSafe AI decisions, XDP firewalls, and K8s AutoSOC β running live in your browser. Pick scenarios, earn XP, earn badges.
Pure JS Β· No backend Β· No libraries
π΄ Ring 0 β π΅ Ring 3 β π§ TypeSafe β βΈοΈ K8s
β‘ 6 Labs Β· 8 Quiz questions Β· 7 Badges
1
Syscall
2
Verifier
3
Ring Buffer
4
TypeSafe AI
5
XDP Firewall
6
K8s AutoSOC
π
Quiz
πΊοΈ The Autonomous SIEM Pipeline β What You Are Building
Each lab corresponds to a real stage in our capstone. A reverse shell detected at Ring 0 becomes an autonomous cluster-wide quarantine in 400ms β zero human in the loop. Animate it below.
π΄
eBPF Hook
sys_enter_execve Ring 0 Β· Kernel
β
π΅
Ring Buffer
BPF_PERF_OUTPUT Zero-copy
β
π
Python Agent
Heuristic filter Ring 3
β
π§
TypeSafe AI
Noul Β· Choice Deterministic
β
βΈοΈ
K8s Operator
NetworkPolicy Quarantine
π‘
Key Insight
PID 442644 executing nc -e /bin/bash was detected and the pod isolated in under 400ms. No human in the loop. No hallucination possible.
π΄ Lab 1 β Syscall Interceptor Β· Ring 0 eBPF
π΄ Lab 1 β Syscall Scenario Simulator Ring 0
Pick a scenario. The eBPF tracepoint fires on sys_enter_execve and extracts PID/PPID from task_struct. Can you identify the real reverse shell vs false positives β like a Tier-2 SOC analyst would?
sys_enter_execvetask_structBPF_PERF_OUTPUT
π Select a scenario β read the eBPF telemetry β make your call
π»Reverse Shellnc -e /bin/bash PID: 442644
π₯οΈGNOME Terminalvte-urlencode-cwd Harmless?
πSSH Loginsshd β bash Lateral move?
πΈοΈWeb Shellapache β bash β nc Critical!
βοΈCron Jobcron β /usr/bin/nc Scheduled?
π§ͺScannernmap β nc Pen test?
π―
Challenge
"GNOME Terminal" matches the 'nc' substring β our naive detector flagged it as a THREAT. This is the real false positive from Test 1. TypeSafe AI (Lab 4) fixes it by evaluating the full parent chain, not just the filename.
Try to slip malicious code past the Verifier. It statically proves all execution paths before a single instruction runs. No sampling. No fuzzing. Mathematical certainty.
Clang JITBPF Verifier
π Select injection type β watch the Verifier pipeline respond
π―
Challenge
Select "bigloop" β Verifier rejects at 1M instruction limit. Same loop as a .ko module = kernel panic. This is why eBPF replaced kernel modules at Meta & Cloudflare.
βοΈ Lab 2B β .ko Module vs eBPF comparison
Same malicious code, two runtimes. See exactly why eBPF is safe and kernel modules are not.
π Select attack β see both outcomes side-by-side
π .ko Kernel Module
π‘οΈ eBPF Program
π‘
The Math
eBPF Verifier models every execution path and proves termination. Deployed by Meta, Cloudflare, and Google in production kernels.
π΅ Lab 3 β BPF Ring Buffer Β· Zero-Copy Data Path
π΅ Lab 3 β Ring Buffer Live Visualizer zero-copy
Visualize BPF_PERF_OUTPUT streaming kernel events to user-space asynchronously. Overwhelm the buffer to watch events drop β exactly what happens during a DDoS if your detector polls too slowly.
BPF_PERF_OUTPUTperf_buffer.poll()
π Increase event rate to simulate a DDoS β watch drops turn red
π―
Challenge
Set rate=100, buffer=8, poll=500ms β drops appear in red. This is why detector.py polls at 100ms. Set rate=5, buffer=64 β zero drops. This balance determines real-world fidelity.
π§ Lab 4 β TypeSafe AI Decision Engine
π° Lab 4A β Slot Machine vs ChatGPT deterministic
TypeSafe Choice always returns one of three hard-coded enums. ChatGPT returns free text β which breaks autonomous pipelines. Feed telemetry and compare both outputs.
Noul primitiveChoice primitive
π Change process + parent β watch typed vs free-text respond
π§ TypeSafe (typed)
π¬ Generic LLM (free text)
π―
Challenge
nc + apache2 β KILL_PROCESS at 97%. vte-urlencode-cwd + gnome-terminal β IGNORE. Same binary, entirely different context. String matching cannot do this.
π Lab 4B β Noul Signal Composer live
TypeSafe Noul must return float 0.0β1.0. Toggle threat signals to build the composite probability. Cross the threshold β trigger the action automatically.
π Toggle signals β watch probability compose in real time
Multi-signal composition is exactly how SIEM correlation rules work β but TypeSafe makes the probability a typed, auditable float that code can act on directly, not a human's gut feeling.
π₯ Lab 5 β XDP CPU Gauge Simulator hardware speed
Simulate a DDoS attack. Traditional iptables processes packets deep inside the kernel. XDP drops them at NIC level before sk_buff allocation. See the CPU delta β this is the Cloudflare model at Terabit scale.
XDP_DROPXDP_PASSiptables
π Ramp up attack β iptables CPU spikes, XDP stays flat
π―
Challenge
5M PPS + iptables β CPU 94% β unresponsive. 5M PPS + XDP β CPU 3% β fully operational. This delta is why Cloudflare absorbs Terabit DDoS attacks without breaking a sweat.
Simulate a live Kubernetes cluster of 12 pods. Inject a reverse shell. Watch the Go Operator detect the label security=compromised and isolate the pod with a NetworkPolicy β the immune system in action.
Reconciler LoopTypeSafe KILLNetworkPolicy
π Click a pod to compromise it manually, or use the action buttons
π΄
eBPF Detects
sys_enter_execve
β
π§
TypeSafe KILL
Noul=0.95
β
π·οΈ
Label Pod
security=compromised
β
βΈοΈ
Reconciler
NetworkPolicy
β
π
Isolated
400ms total
π‘
Self-Healing Infrastructure
The analyst reviews this on Monday morning. The cluster protected itself at 3am Friday. That's the difference between a $2M SIEM contract and a Go operator on a $50/month node.
π SOC Engineer Quiz Β· Test Your Knowledge
π SOC Quiz earn XP
8 questions modeled on real SOC Tier-2 analyst and SRE interview questions. Each correct answer = 25 XP.