Series
Detecting Kubernetes attacks in audit logs
5 posts in this series. Read them in order or jump to any one.
- Detect kubectl exec, attach and port-forward in Audit Logs
How kubectl exec, attach, cp, port-forward and nodes/proxy appear in Kubernetes audit logs, what the command reveals, and how to tell admin work from abuse.
- Kubernetes Secrets Access and Service Account Token Theft
Detect Kubernetes secrets theft and stolen service account tokens in audit logs: cluster-wide lists, read bursts, TokenRequest, public-IP replay, can-i recon.
- Kubernetes RBAC Privilege Escalation: Detect It in Logs
Find Kubernetes RBAC privilege escalation in audit logs: cluster-admin bindings, escalate, bind and impersonate verbs, impersonated calls, anonymous grants.
- Privileged Pods and Container Escape: Audit Log Indicators
Spot container escape preparation in Kubernetes audit logs: privileged pods, hostPID, hostNetwork, hostPath of / or runtime sockets, kube-system DaemonSets.
- Crypto-Mining in Kubernetes: Detect It in Audit Logs
Detect crypto-mining in Kubernetes clusters from audit logs: miner images and arguments, unusual registries, CronJob and DaemonSet persistence, and clean-up.