Terminology Index

Glossary

23 terms starting with "K"

Open concept maps

Showing 1-23 of 23 terms

K
23

Kubernetes Detection

Detecting threats and malicious activity in Kubernetes environments, by monitoring audit logs, runtime behavior, and configuration for signs of attacks like privilege escalation, container escapes, or abuse of the cluster API.

Kubernetes detection focuses on spotting adversary activity across the cluster: suspicious Kubernetes API calls in audit logs, anomalous container runtime behavior, signs of privilege escalation or container escape, and misuse of service accounts or RBAC. Because Kubernetes is complex and dynamic, detection draws on its audit log, runtime sensors, and configuration monitoring. It is a core part of protecting containerized workloads, complementing image scanning and admission control with runtime visibility.

Introduced in: Cloud Workload Protection

Examples

  • Alerting on suspicious Kubernetes API calls in the audit log.
  • Detecting a container escape attempt through runtime monitoring.
  • Spotting abuse of a service account's RBAC permissions.

No related terms linked yet.