/awesome-kubernetes-threat-detection

A curated list of resources about detecting threats and defending Kubernetes systems.

Awesome Kubernetes (K8s) Threat Detection Awesome

A curated list of resources about detecting threats and defending Kubernetes systems.

Contents

Books

Conferences

Talks and videos

All of these videos can also be found in this YouTube playlist.

Detection

Hardening

Attacks

Supply Chain

Networking

Blogs and Articles

Detection

Hardening

Attacks

TTPs / Attack Matrices

Tools

Detection

Hardening

  • seccomp - "can be used to sandbox the privileges of a process, restricting the calls it is able to make from userspace into the kernel."
  • AppArmor - "AppArmor is a Linux kernel security module that supplements the standard Linux user and group based permissions to confine programs to a limited set of resources. AppArmor can be configured for any application to reduce its potential attack surface and provide greater in-depth defense."
  • Kubernetes Network Policy Recipes

Simulation / Experimentation

Attack

Misc

Detection Rules and Analytics

People

All the twitter accounts below are on this Twitter list: awesome-k8-threat-detect