Terminology Index
Glossary
23 terms starting with "K"
Showing 1-23 of 23 terms
Kubernetes Detection
Detecting threats and malicious activity in Kubernetes environments, by monitoring audit logs, runtime behavior, and configuration for signs of attacks like privilege escalation, container escapes, or abuse of the cluster API.
Kubernetes detection focuses on spotting adversary activity across the cluster: suspicious Kubernetes API calls in audit logs, anomalous container runtime behavior, signs of privilege escalation or container escape, and misuse of service accounts or RBAC. Because Kubernetes is complex and dynamic, detection draws on its audit log, runtime sensors, and configuration monitoring. It is a core part of protecting containerized workloads, complementing image scanning and admission control with runtime visibility.
Introduced in: Cloud Workload Protection
Examples
- Alerting on suspicious Kubernetes API calls in the audit log.
- Detecting a container escape attempt through runtime monitoring.
- Spotting abuse of a service account's RBAC permissions.
No related terms linked yet.
