/analyzing-kubernetes-audit-logs
Analyze Kubernetes API audit logs to detect high-risk behaviors (privilege escalation, sec.
Analyze Kubernetes API audit logs to detect high-risk behaviors (privilege escalation, secret access, lateral movement patterns) and produce actionable detection and response artifacts.
Category
Security
Execution
6 steps, sequential + gated
Goal
Analyze Kubernetes API audit logs to detect high-risk behaviors (privilege escalation, secret access, lateral movement patterns) and produce actionable detection and response artifacts.
Scope
Applies to
- +Analyze Kubernetes audit logs
- +Investigate suspicious Kubernetes API activity
- +Create detections for exec/secrets/RBAC abuse
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Analyze Kubernetes audit logs""Investigate suspicious Kubernetes API activity""Create detections for exec/secrets/RBAC abuse""Validate SOC coverage for Kubernetes attack techniques"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01Parsing logic must preserve original event fields for traceability.
- 02High-risk event classes are explicitly monitored (`pods/exec`, secret access, RBAC mutations, privileged pod creation, unauthenticated access).
- 03Detection outputs must distinguish confirmed suspicious activity from expected admin operations.
- 04Investigation artifacts must be suitable for SOC handoff and replay.
Procedure
- Step 1Step 1 — **Ingest and normalize logs**
- Step 2Step 2 — **Apply high-risk detection rules**
- Step 3Step 3 — **Correlate and enrich**
- Step 4Step 4 — **Classify findings**
- Step 5Step 5 — **Generate detection artifacts**
- Step 6Step 6 — **Incident handoff and response support**
Outputs
- ▸Structured audit analysis report with severity-ranked findings.
- ▸Event timeline highlighting suspicious activity chains.
- ▸Detection rule/query package for SOC/SIEM integration.
- ▸Tuning notes and suppression candidates for noisy expected behavior.
Review Gate
- [ ]Core high-risk event categories are covered by explicit detections.
- [ ]Findings include enough context for analyst action.
- [ ]Event evidence is traceable back to raw audit records.
- [ ]Detection package is reproducible and suitable for automation.
- [ ]False-positive handling guidance is documented.