Session 3: Detecting VoidLink Malware with Tetragon - How to Protect Against Malware There are serious OS level vulnerabilities found every day right now, thanks to LLMs analyzing the code faster than ever before. This leads to even more sophisticated malware like Voidlink - and leaves security experts with a big question: how can we deal with this? The answer: Tetragon. In this hands-on session, we observe the Voidlink attack chain in a safe sandbox and the use Tetragon’s eBPF based policies to detect and block the malware at the Kernel level. By working through a real attack scenario, you’ll learn how to observe such an attack, how to write tracing policies, apply enforcement actions, and create an detection policy. What You’ll Learn How a multi stage malware is operating How it can be observed on Kernel level Why the process tree analysis is crucial and how it can help Writing a tracing policy to detect process masquerading Applying actions to terminate malicious processes Writing detection policies Join us to master the final step in VM and Kubernetes security: detecting and killing complex malware on your hosts clarity, confidence, and real-world trust policies.