analyzing-kubernetes-audit-logs
Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from the event patterns. Use when investigating a suspected cluster compromise, reconstructing what an attacker did through the API server, or writing Kubernetes-specific detection content. Keywords: audit policy, audit log, kube-apiserver, exec into pod, RBAC change, anonymous access, detection rules. Do not use for syscall-level detection inside a running container - use detecting-container-runtime-threats-with-falco. '
Source facts
- Repository
- mukul975/Anthropic-Cybersecurity-Skills
- Last source activity
- August 23, 2026 at 15:15
- Detected SKILL.md language
- English
- Stars
- 33,552
- Forks
- 4,068
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.
Showing SKILL.md
- name
- analyzing-kubernetes-audit-logs
- description
- Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from the event patterns. Use when investigating a suspected cluster compromise, reconstructing what an attacker did through the API server, or writing Kubernetes-specific detection content. Keywords: audit policy, audit log, kube-apiserver, exec into pod, RBAC change, anonymous access, detection rules. Do not use for syscall-level detection inside a running container - use detecting-container-runtime-threats-with-falco. '
- domain
- cybersecurity
- subdomain
- container-security
- tags
- ["kubernetes-security","container-security","audit-log-analysis","rbac","privilege-escalation","k8s-api-server","threat-detection"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- nist_csf
- ["PR.PS-01","PR.IR-01","ID.AM-08","DE.CM-01"]
- mitre_attack
- ["T1610","T1613","T1078","T1552.007"]