Better Together: Real Time Threat Detection for Kubernetes with Atomic Red Tests & Falco
ID: 62d143ab-7219-52be-9402-26c1e76840c6
STIX ID: report--62d143ab-7219-52be-9402-26c1e76840c6
Feed Name: Black Hills Infosec Blog
This tutorial demonstrates deploying Atomic Red Team in a Kubernetes lab and validating real-time detections with the Falco open-source IDS, mapping simulations to MITRE ATT&CK (e.g., bulk file deletion T1070.004, PAM manipulation T1556.003, masquerading T1036.005, log tampering T1070.002, command history clearing T1070.003, and kernel module injection T1014). It covers installation via Helm, running tests, filtering noisy alerts, and addresses a detection gap for RC script persistence (T1037.004) by creating and deploying a custom Falco rule—showcasing practical detection engineering for cloud-native environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
