← Back to feed
research Elastic Security Labs

How to correlate Kubernetes audit logs with container runtime data

Elastic Security Labs • • Docker

Two fields join the Kubernetes API to what ran inside the pod, and one turns up a container escape your process events never recorded.

Read the full story Elastic Security Labs →

Related Coverage

research Introducing AlertZero: Inbox zero for your alert queue Elastic Security Labs · Oct 8 research Japan Adopts Proactive Cyber Defense Strategy Recorded Future · Oct 8 research Evolution of Web3 in Cloud Supply Chain Attacks Unit 42 · Oct 7