Tracee Runtime Security Series: Easy Installation on Kubernetes
ID: 4d30d6f7-6ca3-51d7-9a01-8bbf7d8cacd5
STIX ID: report--4d30d6f7-6ca3-51d7-9a01-8bbf7d8cacd5
Feed Name: Aqua Security Blog
Threat Score
This blog shows how to deploy and validate Tracee (an open-source runtime security tool) in a Kubernetes cluster and demonstrates detection of a simulated real-world attack: a command-injection exploit against an OWASP Mutillidae app that yields a reverse shell, subsequent use of kubectl and a service-account token for privilege escalation, and theft of the cluster CA private key — with Tracee signatures and logs capturing each malicious action.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
