← docsSecurity

/analyzing-kubernetes-audit-logs

Analyze Kubernetes API audit logs to detect high-risk behaviors (privilege escalation, sec.

Analyze Kubernetes API audit logs to detect high-risk behaviors (privilege escalation, secret access, lateral movement patterns) and produce actionable detection and response artifacts.

Category

Security

Execution

6 steps, sequential + gated

Goal

Analyze Kubernetes API audit logs to detect high-risk behaviors (privilege escalation, secret access, lateral movement patterns) and produce actionable detection and response artifacts.

Scope

Applies to

  • +Analyze Kubernetes audit logs
  • +Investigate suspicious Kubernetes API activity
  • +Create detections for exec/secrets/RBAC abuse

Does not cover

  • −Trivial changes outside the workflow domain

Triggers

"Analyze Kubernetes audit logs""Investigate suspicious Kubernetes API activity""Create detections for exec/secrets/RBAC abuse""Validate SOC coverage for Kubernetes attack techniques"

Inputs

  • →Context: environment/system affected
  • →Scope: change boundary
  • →Constraints: policy or hard rules

Invariants

  • 01Parsing logic must preserve original event fields for traceability.
  • 02High-risk event classes are explicitly monitored (`pods/exec`, secret access, RBAC mutations, privileged pod creation, unauthenticated access).
  • 03Detection outputs must distinguish confirmed suspicious activity from expected admin operations.
  • 04Investigation artifacts must be suitable for SOC handoff and replay.

Procedure

  1. Step 1Step 1 — **Ingest and normalize logs**
  2. Step 2Step 2 — **Apply high-risk detection rules**
  3. Step 3Step 3 — **Correlate and enrich**
  4. Step 4Step 4 — **Classify findings**
  5. Step 5Step 5 — **Generate detection artifacts**
  6. Step 6Step 6 — **Incident handoff and response support**

Outputs

  • ▸Structured audit analysis report with severity-ranked findings.
  • ▸Event timeline highlighting suspicious activity chains.
  • ▸Detection rule/query package for SOC/SIEM integration.
  • ▸Tuning notes and suppression candidates for noisy expected behavior.

Review Gate

  • [ ]Core high-risk event categories are covered by explicit detections.
  • [ ]Findings include enough context for analyst action.
  • [ ]Event evidence is traceable back to raw audit records.
  • [ ]Detection package is reproducible and suitable for automation.
  • [ ]False-positive handling guidance is documented.