<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Kubernetes Forensics — Blog</title>
    <link>https://www.kubernetesforensics.com/de/blog</link>
    <description>Latest from Blog</description>
    <language>de</language>
    <lastBuildDate>Sun, 27 Sep 2026 20:41:49 GMT</lastBuildDate>
    <atom:link href="https://www.kubernetesforensics.com/de/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Was Kubernetes-Audit-Logs nicht zeigen und was hilft</title>
      <link>https://www.kubernetesforensics.com/de/blog/kubernetes-audit-log-limitations</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/kubernetes-audit-log-limitations</guid>
      <description>Die blinden Flecken von Kubernetes-Audit-Logs: Aktivität in Containern, Zugriffe auf Kubelet und etcd, Policy-Lücken, fälschbare Felder und was sie schließt.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes-Angriff Schritt für Schritt: fiktiver Incident</title>
      <link>https://www.kubernetesforensics.com/de/blog/kubernetes-incident-walkthrough-fictional</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/kubernetes-incident-walkthrough-fictional</guid>
      <description>Ein fiktiver Kubernetes-Incident im Audit-Log: exponiertes Dashboard-Token, can-i-Aufklärung, Secret-Diebstahl, privilegiertes DaemonSet, XMRig-CronJob.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Krypto-Mining in Kubernetes in Audit-Logs erkennen</title>
      <link>https://www.kubernetesforensics.com/de/blog/kubernetes-cryptomining-detection</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/kubernetes-cryptomining-detection</guid>
      <description>Krypto-Mining in Kubernetes-Clustern über Audit-Logs erkennen: Miner-Images und -Argumente, unübliche Registries, Persistenz per CronJob und DaemonSet.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Privilegierte Pods und Container-Escape: Hinweise im Log</title>
      <link>https://www.kubernetesforensics.com/de/blog/privileged-pods-container-escape</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/privileged-pods-container-escape</guid>
      <description>Vorbereitung eines Container-Escapes in Kubernetes-Audit-Logs erkennen: privilegierte Pods, hostPID, hostNetwork, hostPath auf / und DaemonSets in kube-system.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes-RBAC-Rechteausweitung in Audit-Logs erkennen</title>
      <link>https://www.kubernetesforensics.com/de/blog/kubernetes-rbac-privilege-escalation</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/kubernetes-rbac-privilege-escalation</guid>
      <description>Kubernetes-RBAC-Rechteausweitung in Audit-Logs finden: Bindings an cluster-admin, Verben escalate, bind und impersonate, Impersonation und anonymer Zugriff.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes-Secrets und Diebstahl von Service-Account-Tokens</title>
      <link>https://www.kubernetesforensics.com/de/blog/kubernetes-secrets-service-account-token-theft</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/kubernetes-secrets-service-account-token-theft</guid>
      <description>Secret-Diebstahl und gestohlene Service-Account-Tokens in Kubernetes-Audit-Logs erkennen: clusterweite Lists, Häufungen, TokenRequest, öffentliche IPs.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>kubectl exec, attach und port-forward in Audit-Logs finden</title>
      <link>https://www.kubernetesforensics.com/de/blog/detect-kubectl-exec-port-forward</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/detect-kubectl-exec-port-forward</guid>
      <description>Wie kubectl exec, attach, cp, port-forward und nodes/proxy in Kubernetes-Audit-Logs erscheinen, was der Befehl verrät und wie Sie Missbrauch erkennen.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes-Audit-Logs im Browser analysieren: Anleitung</title>
      <link>https://www.kubernetesforensics.com/de/blog/analyze-kubernetes-audit-logs</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/analyze-kubernetes-audit-logs</guid>
      <description>Kubernetes-Audit-Log-Analyse Schritt für Schritt mit einem kostenlosen Browser-Tool: EKS-, GKE-, AKS- oder Roh-Exporte laden, Urteil und Timeline lesen.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Audit-Logs in EKS, GKE und AKS aktivieren und exportieren</title>
      <link>https://www.kubernetesforensics.com/de/blog/eks-gke-aks-audit-logs</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/eks-gke-aks-audit-logs</guid>
      <description>Kubernetes-Audit-Logs auf Amazon EKS, Google GKE und Azure AKS aktivieren und exportieren: wo sie liegen, was die verwaltete Policy weglässt, Export-Befehle.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes-Audit-Policy: was Sie für Forensik loggen sollten</title>
      <link>https://www.kubernetesforensics.com/de/blog/kubernetes-audit-policy-for-forensics</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/kubernetes-audit-policy-for-forensics</guid>
      <description>Eine Kubernetes-Audit-Policy, die Beweise für Untersuchungen erfasst (exec, RBAC, Workloads, Tokens), ohne Secrets zu loggen oder im Rauschen zu versinken.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes-Audit-Log-Format: Anatomie eines Audit-Events</title>
      <link>https://www.kubernetesforensics.com/de/blog/kubernetes-audit-event-anatomy</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/kubernetes-audit-event-anatomy</guid>
      <description>Das Kubernetes-Audit-Log-Format Feld für Feld: Stages, Level, user, sourceIPs, objectRef, responseStatus, Annotationen und was davon in der Forensik zählt.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes Incident Response mit API-Server-Audit-Logs</title>
      <link>https://www.kubernetesforensics.com/de/blog/kubernetes-incident-response-audit-logs</link>
      <guid isPermaLink="true">https://www.kubernetesforensics.com/de/blog/kubernetes-incident-response-audit-logs</guid>
      <description>Kubernetes Incident Response aus der Praxis: welche Audit-Log-Beweise Sie sichern, welche Fragen Sie klären, welche Angriffe Sie suchen, wie Sie eindämmen.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>