Kubernetes Audit Log “Gotchas”
ID: ccbbbfa9-19ac-55cc-bae6-ca4f53cda702
STIX ID: report--ccbbbfa9-19ac-55cc-bae6-ca4f53cda702
Feed Name: Wiz Blog
The report examines Kubernetes audit logging as a foundation for detection and forensics, detailing practical challenges across cloud providers and self-hosted clusters—namely inconsistent default logging policies (often disabled by default), vendor-specific and altered log formats that break portability of detection rules, opaque audit policies controlled by CSPs, and performance/latency and cost trade-offs when centralizing telemetry. These issues can cause missed detections (e.g., privilege escalation, lateral movement), increase maintenance overhead, and hinder investigations; the authors recommend normalizing logs, centralizing them (e.g., SIEM), and augmenting audit telemetry with dynamic admission controllers, cloud control-plane logs, and network visibility to achieve consistent, actionable insights.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
