THREATOPS
THREAT OPSThreat News › How to correlate Kubernetes audit logs with container runtime data

How to correlate Kubernetes audit logs with container runtime data

medelastic_securityPublished 2026-09-03

<p>If you already ship Kubernetes (K8s) audit logs and Defend for Containers (D4C) into Elastic, you still have to join them by hand, and neither source is complete on its own. In our lab, a compromised workload service account ran discovery, read secrets, minted a token, created a privileged pod, and execed into it to attempt a container escape. The escape wrappers, <code>nsenter</code> and <code

Indicators of compromise

Original source: https://www.elastic.co/security-labs/threat-command/kubernetes-audit-logs-container-escape