How to correlate Kubernetes audit logs with container runtime data
Security Labs

How to correlate Kubernetes audit logs with container runtime data
Two fields join the Kubernetes API to what ran inside the pod, and one turns up a container escape your process events never recorded.
Now available: the 2025 State of Detection Engineering at Elastic
Security Labs

Now available: the 2025 State of Detection Engineering at Elastic
The 2025 State of Detection Engineering at Elastic explores how we create, maintain, and assess our SIEM and EDR rulesets.
