BigHugger
sk Skill · mukul975

analyzing-kubernetes-audit-logs

Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from the event patterns. Use when investigating a suspected cluster compromise, reconstructing what an attacker did through the API server, or writing Kubernetes-specific detection content. Keywords: audit policy, audit…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
pythonthreat-detectionk8s-api-serverprivilege-escalationrbacaudit-log-analysiscontainer-securityPythonkubernetes-security
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python