logo

Tracee Runtime Security Series: Easy Installation on Kubernetes

ID: 4d30d6f7-6ca3-51d7-9a01-8bbf7d8cacd5

STIX ID: report--4d30d6f7-6ca3-51d7-9a01-8bbf7d8cacd5

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2021-10-12

Date Updated: 2026-04-26

...
...

This blog shows how to deploy and validate Tracee (an open-source runtime security tool) in a Kubernetes cluster and demonstrates detection of a simulated real-world attack: a command-injection exploit against an OWASP Mutillidae app that yields a reverse shell, subsequent use of kubectl and a service-account token for privilege escalation, and theft of the cluster CA private key — with Tracee signatures and logs capturing each malicious action.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.