Skip to the card

Card 403 of 9842026-09-28 issue

Observed arrival · 2026-09-28

Kubernetes Forensics: Was Your Cluster Compromised?

kubernetesforensics.com Visit website
Editorial interest 78/100 Selection signal · not a rating of the site

A browser-based analyzer for Kubernetes API-server audit logs that presents a verdict, findings, an attack timeline, and a remediation checklist.

Landing page captured for the 2026-09-28 issue.
For
Kubernetes administrators and incident responders
Worth noticing
The guide warns that logs cover only the enabled retention window and recommends collecting from every control-plane node.

Field notes

The collection guide gives a control-plane shell procedure for locating and copying audit logs, then shows a workstation command for fetching files from each node. It warns that audit evidence starts only when logging is enabled and lasts only through the configured retention window; the page cites 30 days as the GKE Data Access default. Its sample attack is explicitly fictional, progressing from an exposed token through reconnaissance and secret listing to a privileged DaemonSet and miner CronJob.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Regulated by Arithmetic

233,109 arrived 1,000 judged 984 catalogued Enter the complete issue
kubernetesforensics.com

Landing page observed 2026-09-28. The live site may have changed.