Hiding in Plaintext Sight: Abusing The Lack of Kubernetes Auditing Policies

Jared Stroud Cloud Security Researcher – Lacework Labs Key Points: Kubernetes Audit Policies are critical for cluster-level visibility. Kubernetes Annotations allow for arbitrary storage and can be abused for malicious activity. Kubernetes API endpoints create a novel C2 channel that may be difficult to audit or detect within organizations.   Introduction to Kubernetes Audit Log [...]

Read More...

The post Hiding in Plaintext Sight: Abusing The Lack of Kubernetes Auditing Policies appeared first on Lacework.

Article Link: Hiding in Plaintext Sight: Abusing The Lack of Kubernetes Auditing Policies - Lacework