← Back to feed
research
Elastic Security Labs
How to correlate Kubernetes audit logs with container runtime data
Two fields join the Kubernetes API to what ran inside the pod, and one turns up a container escape your process events never recorded.
Read the full story
Elastic Security Labs →