Auditing Observability Pipeline Collector Trust

Audit telemetry collectors and observability pipelines for trust they should not extend: a collector endpoint that ingests metrics, logs, or traces without authenticating the sender, a processor that executes or forwards based on attacker-controllable telemetry fields, a collector running with broad credentials whose exporters reach sensitive destinations, and an ingestion path where log or trace content becomes a command, a query, or a downstream request. Covers agents and gateway collectors for logs, metrics, and traces, where the pipeline reads data from many sources and acts on it. Use when a telemetry collector ingests from workloads or the network and forwards, transforms, or stores that data. The unauthenticated or attacker-shaped telemetry is the source, the collector processor or exporter is the sink, and the unauthenticated ingestion or the acted-upon field is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-observability-pipeline-collector-trust commit 2b2fc71168

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-observability-pipeline-collector-trust