Observed arrival · 2026-09-28
Kubernetes Forensics: Was Your Cluster Compromised?
A browser-based analyzer for Kubernetes API-server audit logs that presents a verdict, findings, an attack timeline, and a remediation checklist.
- For
- Kubernetes administrators and incident responders
- Worth noticing
- The guide warns that logs cover only the enabled retention window and recommends collecting from every control-plane node.
Field notes
The collection guide gives a control-plane shell procedure for locating and copying audit logs, then shows a workstation command for fetching files from each node. It warns that audit evidence starts only when logging is enabled and lasts only through the configured retention window; the page cites 30 days as the GKE Data Access default. Its sample attack is explicitly fictional, progressing from an exposed token through reconnaissance and secret listing to a privileged DaemonSet and miner CronJob.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue