THREAT OPS › Threat News › AWS EKS forensics: data sources and investigation tooling
AWS EKS forensics: data sources and investigation tooling
Investigating a compromise in Amazon EKS means piecing together evidence spread across three layers: the managed Kubernetes control plane, the worker nodes, and the surrounding AWS services. This article maps the data sources an EKS cluster exposes for digital forensics and threat hunting, and the tooling used to correlate them, from the Kubernetes audit log down to the AWS identity of the nodes.