KNOWLEDGE BASE
SECURITY
LIBRARY.
The definitive glossary of autonomous security, cloud-native architecture, and runtime defense concepts.
Adaptive Coverage
Adaptive Coverage
Opsonance's core architecture that intelligently rotates deep-inspection resources across containerized workloads based on real-time risk scoring and telemetry probability.
Agent Escape
Agent Escape
A critical vulnerability where an autonomous AI agent breaches its intended sandbox or runtime boundaries, executing unapproved actions on the underlying host.
Agentic Attack
Agentic Attack
A coordinated, autonomous cyberattack executed by an AI agent capable of adapting to defenses, writing novel exploits, and autonomously moving laterally.
AI Agent
AI Agent
An autonomous software system driven by a large language model that perceives its environment, makes decisions, and executes tool calls to achieve complex objectives.
AI Threat Defense
AI Threat Defense
Opsonance's dedicated security paradigm designed to monitor, intercept, and contain malicious actions initiated by compromised or rogue AI agents.
API Server Abuse
API Server Abuse
The weaponization of stolen Service Account tokens to query or manipulate the central Kubernetes control plane.
Autonomous Agent
Autonomous Agent
A system designed to operate over extended periods without human intervention, creating unique risks if its execution logic is hijacked.
Autonomous Remediation
Autonomous Remediation
Opsonance's capability to execute instant, policy-driven responses—such as killing a process or cordoning a node—when a critical threat is confirmed.
Behavioral Fingerprinting
Behavioral Fingerprinting
The automated profiling of a workload or AI agent's baseline state, used by Patrol Agents to instantly flag anomalous deviations.
Casino Architecture
Casino Architecture
The mathematical model underlying Opsonance, ensuring a deterministic probability of catching malicious behavior by dynamically shifting inspection resources.
Cloud Metadata
Cloud Metadata
A service running in cloud environments (like IMDSv2 on AWS) providing instance-specific configuration and credentials, often targeted by SSRF or container escapes.
Container Escape
Container Escape
A post-exploitation technique where an attacker breaks out of a container's isolated namespaces to achieve root-level execution on the underlying host node.
Container Runtime
Container Runtime
The underlying software component (such as containerd or runc) responsible for fetching, unpacking, and executing container images on a host system.
Credential Theft
Credential Theft
The unauthorized harvesting of sensitive authentication tokens, SSH keys, or cloud access tokens from compromised workloads to facilitate further access.
Deep-Inspection
Deep-Inspection
Opsonance's intensive, kernel-level telemetry mode that hooks system calls and eBPF events to perform rigorous behavioral analysis on a workload.
Discovery
Discovery
A tactical phase where an attacker maps out the internal network, enumerates running services, and identifies potential targets for lateral movement.
Dynamic Attachment
Dynamic Attachment
The capability of a Sentinel to instantly hook into a running workload without requiring a restart, sidecar injection, or application downtime.
eBPF
eBPF
A revolutionary kernel technology allowing programs to run securely within the Linux kernel, used extensively for high-performance security observability.
Execution Sandbox
Execution Sandbox
An isolated boundary (often utilizing gVisor or microVMs) designed to safely contain the unverified tool calls of an AI agent.
Exfiltration
Exfiltration
The unauthorized transfer or smuggling of sensitive data out of a compromised environment to an external, attacker-controlled location.
Host Takeover
Host Takeover
The absolute compromise of the underlying Kubernetes worker node, granting an attacker dominion over all workloads running on that machine.
Immutable Infrastructure
Immutable Infrastructure
The architectural principle that containers should never change at runtime, turning any unexpected file modification or process execution into a glaring anomaly.
Indirect Prompt Injection
Indirect Prompt Injection
A threat where an AI agent unknowingly ingests malicious instructions hidden inside external data sources (like websites or parsed emails).
Kernel Rootkit
Kernel Rootkit
A deeply embedded malicious module that operates at Ring 0, capable of blinding traditional user-space security tools by altering the OS fabric itself.
Kubernetes
Kubernetes
The industry-standard orchestration system for automating the deployment, scaling, and management of containerized applications and cloud-native infrastructure.
Lateral Movement
Lateral Movement
The process by which an attacker, having gained initial access to a single system, incrementally moves to other workloads or nodes within the network.
Linux Namespaces
Linux Namespaces
The fundamental isolation technology (covering PID, Mount, Network, etc.) that creates the illusion of a containerized environment.
Model Context
Model Context
The working memory and prompt environment of a large language model. If poisoned with malicious instructions, it leads directly to indirect prompt injection.
Model Poisoning
Model Poisoning
The deliberate corruption of an AI model's training or fine-tuning data to introduce backdoors or bias its future decision-making.
Nekron
Nekron
An advanced, autonomous adversary emulation engine designed to continuously stress-test runtime environments and validate Opsonance's detection logic.
Patrol Agent
Patrol Agent
A lightweight Opsonance telemetry node that monitors baseline workload behavior and orchestrates the deployment of heavy Sentinel resources when anomalies are detected.
Persistence
Persistence
Techniques utilized by attackers to maintain long-term access to a compromised system, ensuring their backdoors or rootkits survive reboots and application restarts.
Privilege Escalation
Privilege Escalation
The exploitation of a bug, design flaw, or misconfiguration to gain elevated access to resources normally protected from an application or user.
Process Lineage
Process Lineage
The execution graph maintained by Opsonance that tracks parent-child process relationships to determine the exact origin of a malicious action.
Prompt Injection
Prompt Injection
A severe AI vulnerability where untrusted user input is crafted to manipulate an LLM's instructions, forcing the model to ignore safety guardrails or execute malicious commands.
RBAC Misconfiguration
RBAC Misconfiguration
Flaws in Role-Based Access Control that allow a workload to possess excessive cloud permissions, facilitating privilege escalation.
Risk Engine
Risk Engine
The mathematical core of Opsonance that calculates real-time threat scores to dictate exactly when and where Sentinels are deployed.
Runtime Security
Runtime Security
The active defense layer designed to detect and block threats occurring while an application is actively executing in memory, going beyond static image scanning.
Sentinel Workload
Sentinel Workload
The heavy, deep-inspection component of Opsonance that attaches dynamically to running pods to stream high-fidelity kernel events and enforce security policies.
Sentinels
Sentinels
Active patrol agents deployed directly into workloads for continuous, deep-inspection of kernel telemetry and runtime execution.
Service Account
Service Account
A non-human machine identity used by workloads, such as Kubernetes pods, to authenticate and interact with APIs and internal cloud services.
Special Forces
Special Forces
Reserve patrol agents held dynamically by the Opsonance platform, dropped into critical zones only during high-severity threat detections or active attacks.
Supply Chain Compromise
Supply Chain Compromise
The infiltration of malicious code into container images or dependencies long before the workload ever reaches the runtime environment.
Synapse
Synapse
The central intelligence nervous system of Opsonance, responsible for ingesting, correlating, and analyzing millions of high-fidelity kernel events in real time.
Syscall
Syscall
The fundamental interface between an application running in user space and the Linux kernel, acting as the ultimate choke point for runtime security monitoring.
System Call Hooking
System Call Hooking
The technique utilized by Opsonance Sentinels to intercept application requests at the kernel boundary, providing unforgeable visibility.
Tool Abuse
Tool Abuse
A scenario where an AI agent's legitimate capabilities (like running shell commands or reading files) are co-opted to execute malicious actions against the host.
Workload Identity
Workload Identity
The cryptographic identity assigned to a specific runtime process or container, tying its behavioral actions directly to authorized cloud permissions.
XDP (eXpress Data Path)
XDP (eXpress Data Path)
A high-performance eBPF capability often abused by advanced rootkits to intercept and manipulate network packets before they reach the OS stack.