THREAT OPS › Threat News › How to correlate Kubernetes audit logs with container runtime data
How to correlate Kubernetes audit logs with container runtime data
<p>If you already ship Kubernetes (K8s) audit logs and Defend for Containers (D4C) into Elastic, you still have to join them by hand, and neither source is complete on its own. In our lab, a compromised workload service account ran discovery, read secrets, minted a token, created a privileged pod, and execed into it to attempt a container escape. The escape wrappers, <code>nsenter</code> and <code
Indicators of compromise
- 43a60b86c1ad3c9d618d571581556f306d2c4b00sha1
- https://elastic.github.io/detection-rules-explorer/url
- authentication.kubernetes.iodomain
- kubernetes.iodomain
- static-www.elastic.codomain
- kubernetes.audit.user.extra.authentication.kubernetes.iodomain