Výsledky hledání

výrobce: Kubernetes× typ: návod× v celém archivu zrušit filtry

1 karet z 1 položek CZ · EN/orig

1

How to correlate Kubernetes audit logs with container runtime data

If you already ship Kubernetes (K8s) audit logs and Defend for Containers (D4C) into Elastic, you still have to join them by hand, and neither source is complete on its own. In our lab, a compromised workload service account ran discovery, read secrets, minted a token, created a privileged pod, and execed into it to attempt a container escape. The escape wrappers, nsenter and chroot, never appeared in the runtime process events. Kubernetes audit logs recorded them in the decoded requestURI.Real…

Kubernetes Elastic US

tg: návod tg: propagace

Elastic Security ·