← Back to feed
research Elastic Security Labs

How to correlate Kubernetes audit logs with container runtime data

Elastic Security Labs Docker

Two fields join the Kubernetes API to what ran inside the pod, and one turns up a container escape your process events never recorded.

Read the full story Elastic Security Labs →

Related Coverage

research Agent Running in the Age of AI Recorded Future · Sep 22 research 21st September – Threat Intelligence Report Check Point Research · Sep 21 research SAML: A fractal of bad design Trail of Bits · Sep 21