Skip to content
Back to skills

Analyzing Kubernetes Audit Logs

ASecurity

Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from the event patterns. Use when investigating a suspected cluster compromise, reconstructing what an attacker did through the API server, or writing Kubernetes-specific detection content. Keywords: audit policy, audit log, kube-apiserver, exec into pod, RBAC change, anonymous access, detection rule...

  • 3 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 2, 2026
ai-agentspythonshellkubernetestestingapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned September 2, 2026

npx -y skills add nuroctane/nur-cli --skill analyzing-kubernetes-audit-logs --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Analyzing Kubernetes Audit Logs?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Analyzing Kubernetes Audit Logs
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nuroctane-analyzing-kubernetes-audit-logs/badge)](https://www.skillsdirectory.com/skills/nuroctane-analyzing-kubernetes-audit-logs)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: analyzing-kubernetes-audit-logs
description: >-
  Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access,
  RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM
  detection rules from the event patterns. Use when investigating a suspected cluster
  compromise, reconstructing what an attacker did through the API server, or writing
  Kubernetes-specific detection content. Keywords: audit policy, audit log, kube-apiserver,
  exec into pod, RBAC change, anonymous access, detection rules. Do not use for syscall-level
  detection inside a running container - use detecting-container-runtime-threats-with-falco.

  '
domain: cybersecurity
subdomain: container-security
tags:
- kubernetes-security
- container-security
- audit-log-analysis
- rbac
- privilege-escalation
- k8s-api-server
- threat-detection
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.IR-01
- ID.AM-08
- DE.CM-01
mitre_attack:
- T1610
- T1613
- T1078
- T1552.007
---

# Analyzing Kubernetes Audit Logs


## When to Use

- When investigating security incidents that require analyzing kubernetes audit logs
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques

## Prerequisites

- Familiarity with container security concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities

## Instructions

Parse Kubernetes audit log files (JSON lines format) to detect security-relevant
events including unauthorized access, privilege escalation, and data exfiltration.

```python
import json

with open("/var/log/kubernetes/audit.log") as f:
    for line in f:
        event = json.loads(line)
        verb = event.get("verb")
        resource = event.get("objectRef", {}).get("resource")
        user = event.get("user", {}).get("username")
        if verb == "create" and resource == "pods/exec":
            print(f"Pod exec by {user}")
```

Key events to detect:
1. pods/exec and pods/attach (shell into containers)
2. secrets access (get/list/watch)
3. clusterrolebindings creation (RBAC escalation)
4. Privileged pod creation
5. Anonymous or system:unauthenticated access

## Examples

```python
# Detect secret enumeration
if verb in ("get", "list") and resource == "secrets":
    print(f"Secret access: {user} -> {event['objectRef'].get('name')}")
```

Files in this skill

  • LICENSE11 KB
  • SKILL.md2.6 KB
  • references/api-reference.md1.6 KB
  • scripts/agent.py7.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…