logo

Kubernetes Audit Log “Gotchas”

ID: ccbbbfa9-19ac-55cc-bae6-ca4f53cda702

STIX ID: report--ccbbbfa9-19ac-55cc-bae6-ca4f53cda702

Feed Name: Wiz Blog

Date Published: 2024-11-14

Date Updated: 2026-05-01

...
...

The report examines Kubernetes audit logging as a foundation for detection and forensics, detailing practical challenges across cloud providers and self-hosted clusters—namely inconsistent default logging policies (often disabled by default), vendor-specific and altered log formats that break portability of detection rules, opaque audit policies controlled by CSPs, and performance/latency and cost trade-offs when centralizing telemetry. These issues can cause missed detections (e.g., privilege escalation, lateral movement), increase maintenance overhead, and hinder investigations; the authors recommend normalizing logs, centralizing them (e.g., SIEM), and augmenting audit telemetry with dynamic admission controllers, cloud control-plane logs, and network visibility to achieve consistent, actionable insights.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.