KNOWLEDGE BASE

SECURITY
LIBRARY.

The definitive glossary of autonomous security, cloud-native architecture, and runtime defense concepts.

Adaptive Coverage

Adaptive Coverage

Opsonance's core architecture that intelligently rotates deep-inspection resources across containerized workloads based on real-time risk scoring and telemetry probability.

Agent Escape

Agent Escape

A critical vulnerability where an autonomous AI agent breaches its intended sandbox or runtime boundaries, executing unapproved actions on the underlying host.

Agentic Attack

Agentic Attack

A coordinated, autonomous cyberattack executed by an AI agent capable of adapting to defenses, writing novel exploits, and autonomously moving laterally.

AI Agent

AI Agent

An autonomous software system driven by a large language model that perceives its environment, makes decisions, and executes tool calls to achieve complex objectives.

AI Threat Defense

AI Threat Defense

Opsonance's dedicated security paradigm designed to monitor, intercept, and contain malicious actions initiated by compromised or rogue AI agents.

API Server Abuse

API Server Abuse

The weaponization of stolen Service Account tokens to query or manipulate the central Kubernetes control plane.

Autonomous Agent

Autonomous Agent

A system designed to operate over extended periods without human intervention, creating unique risks if its execution logic is hijacked.

Autonomous Remediation

Autonomous Remediation

Opsonance's capability to execute instant, policy-driven responses—such as killing a process or cordoning a node—when a critical threat is confirmed.

Behavioral Fingerprinting

Behavioral Fingerprinting

The automated profiling of a workload or AI agent's baseline state, used by Patrol Agents to instantly flag anomalous deviations.

Casino Architecture

Casino Architecture

The mathematical model underlying Opsonance, ensuring a deterministic probability of catching malicious behavior by dynamically shifting inspection resources.

Cloud Metadata

Cloud Metadata

A service running in cloud environments (like IMDSv2 on AWS) providing instance-specific configuration and credentials, often targeted by SSRF or container escapes.

Container Escape

Container Escape

A post-exploitation technique where an attacker breaks out of a container's isolated namespaces to achieve root-level execution on the underlying host node.

Container Runtime

Container Runtime

The underlying software component (such as containerd or runc) responsible for fetching, unpacking, and executing container images on a host system.

Credential Theft

Credential Theft

The unauthorized harvesting of sensitive authentication tokens, SSH keys, or cloud access tokens from compromised workloads to facilitate further access.

Deep-Inspection

Deep-Inspection

Opsonance's intensive, kernel-level telemetry mode that hooks system calls and eBPF events to perform rigorous behavioral analysis on a workload.

Discovery

Discovery

A tactical phase where an attacker maps out the internal network, enumerates running services, and identifies potential targets for lateral movement.

Dynamic Attachment

Dynamic Attachment

The capability of a Sentinel to instantly hook into a running workload without requiring a restart, sidecar injection, or application downtime.

eBPF

eBPF

A revolutionary kernel technology allowing programs to run securely within the Linux kernel, used extensively for high-performance security observability.

Execution Sandbox

Execution Sandbox

An isolated boundary (often utilizing gVisor or microVMs) designed to safely contain the unverified tool calls of an AI agent.

Exfiltration

Exfiltration

The unauthorized transfer or smuggling of sensitive data out of a compromised environment to an external, attacker-controlled location.

Host Takeover

Host Takeover

The absolute compromise of the underlying Kubernetes worker node, granting an attacker dominion over all workloads running on that machine.

Immutable Infrastructure

Immutable Infrastructure

The architectural principle that containers should never change at runtime, turning any unexpected file modification or process execution into a glaring anomaly.

Indirect Prompt Injection

Indirect Prompt Injection

A threat where an AI agent unknowingly ingests malicious instructions hidden inside external data sources (like websites or parsed emails).

Kernel Rootkit

Kernel Rootkit

A deeply embedded malicious module that operates at Ring 0, capable of blinding traditional user-space security tools by altering the OS fabric itself.

Kubernetes

Kubernetes

The industry-standard orchestration system for automating the deployment, scaling, and management of containerized applications and cloud-native infrastructure.

Lateral Movement

Lateral Movement

The process by which an attacker, having gained initial access to a single system, incrementally moves to other workloads or nodes within the network.

Linux Namespaces

Linux Namespaces

The fundamental isolation technology (covering PID, Mount, Network, etc.) that creates the illusion of a containerized environment.

Model Context

Model Context

The working memory and prompt environment of a large language model. If poisoned with malicious instructions, it leads directly to indirect prompt injection.

Model Poisoning

Model Poisoning

The deliberate corruption of an AI model's training or fine-tuning data to introduce backdoors or bias its future decision-making.

Nekron

Nekron

An advanced, autonomous adversary emulation engine designed to continuously stress-test runtime environments and validate Opsonance's detection logic.

Patrol Agent

Patrol Agent

A lightweight Opsonance telemetry node that monitors baseline workload behavior and orchestrates the deployment of heavy Sentinel resources when anomalies are detected.

Persistence

Persistence

Techniques utilized by attackers to maintain long-term access to a compromised system, ensuring their backdoors or rootkits survive reboots and application restarts.

Privilege Escalation

Privilege Escalation

The exploitation of a bug, design flaw, or misconfiguration to gain elevated access to resources normally protected from an application or user.

Process Lineage

Process Lineage

The execution graph maintained by Opsonance that tracks parent-child process relationships to determine the exact origin of a malicious action.

Prompt Injection

Prompt Injection

A severe AI vulnerability where untrusted user input is crafted to manipulate an LLM's instructions, forcing the model to ignore safety guardrails or execute malicious commands.

RBAC Misconfiguration

RBAC Misconfiguration

Flaws in Role-Based Access Control that allow a workload to possess excessive cloud permissions, facilitating privilege escalation.

Risk Engine

Risk Engine

The mathematical core of Opsonance that calculates real-time threat scores to dictate exactly when and where Sentinels are deployed.

Runtime Security

Runtime Security

The active defense layer designed to detect and block threats occurring while an application is actively executing in memory, going beyond static image scanning.

Sentinel Workload

Sentinel Workload

The heavy, deep-inspection component of Opsonance that attaches dynamically to running pods to stream high-fidelity kernel events and enforce security policies.

Sentinels

Sentinels

Active patrol agents deployed directly into workloads for continuous, deep-inspection of kernel telemetry and runtime execution.

Service Account

Service Account

A non-human machine identity used by workloads, such as Kubernetes pods, to authenticate and interact with APIs and internal cloud services.

Special Forces

Special Forces

Reserve patrol agents held dynamically by the Opsonance platform, dropped into critical zones only during high-severity threat detections or active attacks.

Supply Chain Compromise

Supply Chain Compromise

The infiltration of malicious code into container images or dependencies long before the workload ever reaches the runtime environment.

Synapse

Synapse

The central intelligence nervous system of Opsonance, responsible for ingesting, correlating, and analyzing millions of high-fidelity kernel events in real time.

Syscall

Syscall

The fundamental interface between an application running in user space and the Linux kernel, acting as the ultimate choke point for runtime security monitoring.

System Call Hooking

System Call Hooking

The technique utilized by Opsonance Sentinels to intercept application requests at the kernel boundary, providing unforgeable visibility.

Tool Abuse

Tool Abuse

A scenario where an AI agent's legitimate capabilities (like running shell commands or reading files) are co-opted to execute malicious actions against the host.

Workload Identity

Workload Identity

The cryptographic identity assigned to a specific runtime process or container, tying its behavioral actions directly to authorized cloud permissions.

XDP (eXpress Data Path)

XDP (eXpress Data Path)

A high-performance eBPF capability often abused by advanced rootkits to intercept and manipulate network packets before they reach the OS stack.