-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathflowchart.code
More file actions
124 lines (106 loc) · 4.7 KB
/
Copy pathflowchart.code
File metadata and controls
124 lines (106 loc) · 4.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
title Automated Malware Detection and Forensic Response in Kubernetes
// Group 1: Detection & Triggering
Detection and Triggering [color: orange, icon: alert-triangle] {
Falco Sidecar or DaemonSet [icon: shield, color: orange]
YARA Scan [icon: search, color: yellow]
ClamAV Scan [icon: shield, color: yellow]
Syscall Monitoring [icon: activity, color: orange]
Predefined Rules Check [icon: check-square, color: orange]
Malware Alert [shape: oval, icon: alert-circle, color: red]
Kubernetes Lifecycle Webhook [icon: link, color: blue]
Pod PreStop Hook [icon: stop-circle, color: blue]
Admission Webhook [icon: log-in, color: blue]
Lifecycle Alert [shape: oval, icon: alert-circle, color: blue]
Central Control Service [icon: server, color: purple]
}
// Group 2: Evidence Collection
Evidence Collection [color: green, icon: folder-plus] {
Privileged Forensic Pod [icon: lock, color: green]
LiME Memory Dump [icon: cpu, color: green]
Filesystem Snapshot [icon: file-text, color: green]
Process Metadata Collection [icon: list, color: green]
nsenter for Process Data [icon: terminal, color: green]
Privileged DaemonSet Agent [icon: repeat, color: teal]
eBPF Hooks [icon: activity, color: teal]
Event Buffering [icon: database, color: teal]
}
// Group 3: Evidence Storage
Evidence Storage [color: blue, icon: archive] {
Artifact Bundle Creation [icon: package, color: blue]
RAM Dump File [icon: cpu, color: blue]
Filesystem Archive [icon: file, color: blue]
Process Metadata File [icon: file-text, color: blue]
eBPF Log File [icon: file-text, color: blue]
Checksum Generation [icon: hash, color: blue]
Amazon S3 Storage [icon: aws-s3, color: blue]
Server Side Encryption [icon: lock, color: blue]
S3 Versioning [icon: layers, color: blue]
S3 Object Lock [icon: lock, color: blue]
Metadata Logging in DynamoDB [icon: aws-dynamodb, color: blue]
QLDB Ledger Logging [icon: aws-qldb, color: blue]
}
// Group 4: Automated Analysis
Automated Analysis [color: purple, icon: cpu] {
S3 Lambda Trigger [icon: aws-lambda, color: purple]
Memory Analysis with Volatility [icon: cpu, color: purple]
Filesystem Analysis with Autopsy [icon: search, color: purple]
YARA Rule Scan [icon: search, color: yellow]
Analysis Output [icon: file-text, color: purple]
}
// Group 5: Correlation, Scoring & Timeline
Correlation and Scoring [color: pink, icon: bar-chart-2] {
Rule Based Scoring [icon: check-square, color: pink]
Retrieval Augmented Generation [icon: database, color: pink]
LLM Prompt and Output [icon: message-square, color: pink]
Timeline Assembly [icon: clock, color: pink]
}
// Group 6: Reporting
Reporting and Dashboard [color: lightblue, icon: monitor] {
Kibana or QuickSight Dashboard [icon: bar-chart, color: lightblue]
Prioritized Alerts [icon: alert-triangle, color: lightblue]
Evidence Links [icon: link, color: lightblue]
LLM Narrative Panel [icon: message-square, color: lightblue]
Visualizations [icon: pie-chart, color: lightblue]
}
// Relationships
Falco Sidecar or DaemonSet > Syscall Monitoring
Syscall Monitoring > Predefined Rules Check
Predefined Rules Check > Malware Alert
YARA Scan > Malware Alert
ClamAV Scan > Malware Alert
Malware Alert > Central Control Service
Kubernetes Lifecycle Webhook > Pod PreStop Hook
Kubernetes Lifecycle Webhook > Admission Webhook
Pod PreStop Hook > Lifecycle Alert
Admission Webhook > Lifecycle Alert
Lifecycle Alert > Central Control Service
Central Control Service > Privileged Forensic Pod
Central Control Service > Privileged DaemonSet Agent
Privileged Forensic Pod > LiME Memory Dump
Privileged Forensic Pod > Filesystem Snapshot
Privileged Forensic Pod > Process Metadata Collection
Process Metadata Collection > nsenter for Process Data
Privileged DaemonSet Agent > eBPF Hooks
eBPF Hooks > Event Buffering
LiME Memory Dump > Artifact Bundle Creation
Filesystem Snapshot > Artifact Bundle Creation
Process Metadata Collection > Artifact Bundle Creation
Event Buffering > Artifact Bundle Creation
Artifact Bundle Creation > RAM Dump File
Artifact Bundle Creation > Filesystem Archive
Artifact Bundle Creation > Process Metadata File
Artifact Bundle Creation > eBPF Log File
RAM Dump File > Checksum Generation
Filesystem Archive > Checksum Generation
Process Metadata File > Checksum Generation
eBPF Log File > Checksum Generation
Checksum Generation > Amazon S3 Storage
Amazon S3 Storage > Server Side Encryption
Amazon S3 Storage > S3 Versioning
Amazon S3 Storage > S3 Object Lock
Amazon S3 Storage > Metadata Logging in DynamoDB
Amazon S3 Storage > QLDB Ledger Logging
Amazon S3 Storage > S3 Lambda Trigger
S3 Lambda Trigger > Memory Analysis with Volatility
S3 Lambda Trigger > Filesystem Analysis with Autopsy
Filesystem Analysis with Autopsy > YARA Rule Scan