Introduction
Kubernetes threat and attack detection: Introduction
()
1. Ensure Immutability of Containers at Runtime
Understanding immutability
()
Read only filesystem
()
Policy enforcement with VAP
()
2. Use Kubernetes Audit Logs to Monitor Access
Learning objectives
()
Auditing in Kubernetes
()
Define an audit policy
()
Event batching and tuning
()
Configure backend log storage
()
3. Detect Malicious Activity, Threats, and Attacks
Learning objectives
()
Understanding syscall behavioral analysis
()
Using Falco for threat detection
()
Falco host installation
()
Falco Kubernetes installation
()
Falco configuration and rules
()
Falco custom rules in action
()
4. Investigate and Identify Signs of Compromise
Learning objectives
()
MITRE ATT&CK® framework
()
Security event log review
()
Gathering evidence of compromise
()
Practicing Kubernetes security
()
Summary
Kubernetes threat and attack detection: Summary
()