Financial organisations operate in environments where even a short delay in understanding a cyber incident can have serious operational, financial and regulatory consequences. Detecting suspicious activity is essential, but detection alone is not enough. Once an alert has been raised, security teams must determine what happened, how the attack progressed, which systems were affected and what actions are needed to prevent a recurrence.
This transition from detection to investigation is one of the challenges being addressed within the CyberAId project. Through the combined work of its real-time monitoring and digital forensics activities, CyberAId is developing a pipeline that transforms low-level system activity into structured evidence that can support incident reconstruction, root cause analysis and post-incident reporting.
Seeing activity below the application layer
Modern financial infrastructures consist of interconnected payment platforms, banking applications, authentication services and trading systems. Monitoring only the logs generated by these applications may leave important gaps in visibility, particularly when attackers attempt to bypass application-level controls or hide their activity within legitimate system processes.
CyberAId therefore explores the use of extended Berkeley Packet Filter, or eBPF, technology to observe network and system behaviour directly from the operating system kernel. This enables the monitoring of events such as TCP connections and process executions without requiring modifications to the applications being protected.
Within CyberAId, K3Y is developing eBPF-based monitoring tools to capture network connections and process activity in a representative financial environment. The environment includes payment-processing, banking and authentication services, together with legitimate traffic and selected attack scenarios, enabling the ongoing evaluation and refinement of the monitoring approach.
The captured activity is transformed into structured security events containing the contextual information required for further analysis, including timestamps, process information and network communication details. Financial-specific detection rules can then identify patterns such as suspicious connections, connection bursts, unexpected process execution and potential privilege-escalation or data-exfiltration activity.
From monitoring events to security context
Large volumes of low-level events are only useful when they can be organised, queried and presented in a form that security teams can understand.
Within CyberAId, K3Y is integrating the monitoring pipeline with Wazuh and OpenSearch. Events generated by the eBPF monitoring tools are processed through custom decoders and detection rules, indexed for further analysis, and visualized through dedicated dashboards. These dashboards provide an overview of event severity, activity over time, detected attack categories, and critical security events. The resulting monitoring and detection outputs can then feed CyberAId’s broader alert generation and notification workflows.
This integration creates a bridge between kernel-level visibility and operational security monitoring. Instead of examining isolated system events, analysts can access structured information that helps them understand what activity occurred and why it may be important.
However, an alert still represents only the beginning of an investigation.
Reconstructing what happened
CyberAId’s digital forensics and post-incident analysis activities build on the monitoring and detection capabilities developed within the project. Their purpose is to collect and organise relevant evidence, reconstruct incident timelines, identify root causes and map observed behaviour to recognised attack techniques.
For example, a single suspicious outbound connection may not provide enough information to explain an incident. When combined with process execution records, authentication activity, application logs and other available evidence, it can become part of a broader narrative showing when the attack began, which actions followed and how the attacker moved through the affected environment.
The planned forensic workflow will use structured monitoring events and detection outputs from CyberAId’s monitoring tasks, together with security knowledge models, correlated events and escalated alerts. These inputs can support the creation of reconstructed incident timelines, Root Cause Analysis outputs, MITRE ATT&CK mappings and forensic reports.
These forensic outputs can support other CyberAId capabilities by providing structured context for incident reasoning, risk mitigation, analyst investigation and validation within the financial pilot environments.
Financial-specific and privacy-aware investigation
Digital investigations in the financial sector must account for more than technical accuracy. Evidence may contain personal, transactional or commercially sensitive information, while organisations must comply withrequirements related to data protection, operational resilience and incident reporting.
For this reason, CyberAId is also considering chain-of-custody, forensic soundness and privacy-preserving evidence handling. The objective is to support thorough investigations without unnecessarily exposing sensitive business content or personal data.
The project will further refine financial-specific forensic workflows for payment systems, banking platforms and trading infrastructures. Future work will expand the range of evidence sources, improve timeline reconstruction and root cause analysis, strengthen integration with CyberAId security knowledge models and validate the resulting workflows within the project’s pilot environments.
By connecting low-level monitoring with structured forensic investigation, CyberAId aims to help financial organisations move beyond simply detecting suspicious activity. The goal is to provide the context required to understand incidents, respond more effectively and turn every investigation into knowledge that strengthens future cyber resilience.




