Analyzing Kubernetes Audit Logs

Use when parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns. Use when investigating Kubernetes cluster compromise or building k8s-specific SIEM detection rules.

oyi77 0f935e1 3.8 KB Updated 10 repo stars

File contents

oyi77/1ai-skills/tree/main/cybersecurity/analyzing-kubernetes-audit-logs commit 0f935e1c42

Frequently asked questions

npx skillmds add oyi77/analyzing-kubernetes-audit-logs