logo

Three Kubernetes events worth investigating

ID: 1d0a4d87-30e9-5187-b51c-1d1c6815412d

STIX ID: report--1d0a4d87-30e9-5187-b51c-1d1c6815412d

Feed Name: Expel Blog

Date Published: 2022-10-24

Date Updated: 2026-04-27

Author: Dan Whalen

...
...

This short guide describes how to monitor Kubernetes audit logs to detect high-risk events—specifically successful anonymous API authorizations, default service accounts bound to privileged cluster roles, and pods deployed with unexpected container images—and provides practical tips for alerting and investigation to reduce the risk of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.