Field Test 03: 1,000,000 Real eBPF Kernel Events Ingested on UniDB
| EVENT # | TIME (ยตs) | PID (PPID) | UID | PROCESS | SYSCALL | ARGUMENTS | MITRE ATT&CK | CAUSAL LINEAGE | ACTIONS | |
|---|---|---|---|---|---|---|---|---|---|---|
| Loading initial event stream from 1,000,000 event index... | ||||||||||
Indicators of Compromise (IOCs) tagged from the SOC Telemetry Explorer. Tag any suspicious event to share forensic proof with your Threat Intel and Governance teammates.
Engineering transparency: No detection model achieves 100% precision without overfitting or suppressing genuine administrative workflows. Below is the full breakdown of why legitimate operations triggered alerts and our architectural boundary conditions.
Dataset Provenance: Kernel telemetry schemas and attack behavioral profiles are modeled after the public BETH (Behavioral eBPF-based Threat Hunting) honeypot dataset developed by researchers at Imperial College London and KTH Royal Institute of Technology. The dataset reflects authentic eBPF syscall traces from containerized workloads exposed to the internet.
MITRE ATT&CK® Attribution: Attack techniques, tactics, and procedural patterns are mapped to the MITRE ATT&CK® Enterprise Matrix (© 2026 The MITRE Corporation). MITRE and MITRE ATT&CK are registered trademarks of The MITRE Corporation.
Disclaimer: UniDB-Hunter is an independent engineering benchmark and demonstration developed to evaluate raw storage density, CSR causal graph lineage, and SIMD threat-hunting latency over eBPF kernel telemetry. It is not affiliated with, sponsored by, or endorsed by The MITRE Corporation, Imperial College London, or KTH.