Kernel-space intrusion detection using eBPF CO-RE and Rust Stream Core at ~600k EPS ingest throughput (rules disabled). 4-layer AI engine covers 7 MITRE ATT&CK categories with zero loadable kernel modules and <5% CPU overhead.
Explore Nora VisioneBPF intrusion detection attaches sandboxed bytecode programs to kernel tracepoints, streaming syscall, network, and file events to user-space AI engines without loadable kernel modules or per-pod agents. Nora Vision's eBPF CO-RE sensor sustains ~600k EPS ingest throughput (rules disabled, internal audit) from kernel-space via zero-copy Rust pipelines, with <5% CPU overhead at production workloads.
Traditional EDR relies on user-space daemons that can be killed, bypassed, or blinded by rootkits. eBPF programs run in kernel-space, intercepting syscalls before evasion is possible. Nora Vision sustains ~600k EPS ingest throughput with rules disabled (internal audit), compared with legacy user-space agents that impose double-digit CPU overhead at far lower event rates, with no kernel module installation required.
CO-RE uses BTF-enabled bytecode compiled once against generic kernel headers, then relocates field offsets at runtime. The same eBPF object runs on Linux 3.10–6.x kernels without recompilation or kernel headers on target hosts — enabling universal deployment across EKS, GKE, AKS, and bare-metal.
Nora Vision maps kernel events to 7 MITRE ATT&CK tactics: Container Escape (T1611), Fileless Execution (T1620/T1059), Lateral Movement (T1572/T1003), Privilege Escalation (T1548/T1068/T1574), Cryptominer (T1496), Supply Chain (T1195), and APT/C2 (T1071/T1074). The 4-layer AI engine (Sigma rules, Isolation Forest, HMM kill-chain, Active Learning) covers 25+ detection rules.
No. Nora Vision uses eBPF CO-RE programs with BTF support, requiring no kernel modules. CAP_BPF and CAP_PERFMON capabilities suffice on Linux 5.8+ kernels.
The DaemonSet deployment attaches eBPF programs per cgroup/namespace, enriching events with pod name, namespace, and workload labels for precise tenant isolation in alert routing.
Yes. The rootkit detection module monitors DKOM (Direct Kernel Object Manipulation), syscall hook tampering, and LKM hiding using encrypted SQLCipher DB comparison against known-good kernel state.
eBPF Real-Time AI Workload Threat Detection — architecture and performance deep-dive
Singapore-based. Pay after delivery. AI-assisted pipeline with human expert review.