Kubernetes
API server audit logs from EKS, GKE and AKS clusters.
Category
Cloud
Setup
About 30 minutes
Events Wardell reads
API server audit events, exec into pods, RBAC changes
Wardell reads the managed audit log from EKS, GKE or AKS, so there is no DaemonSet to run. Self-managed clusters can ship audit logs over a webhook.
The pack covers exec into production pods, new cluster-admin bindings, privileged pods and secrets read by service accounts that never read them before.
What Wardell watches
Exec and port-forward into production pods
RBAC and cluster-admin binding changes
Privileged pod and host path mounts
Service account behavior baselines
Try it on your own logs
Connect this source with a read-only key. Within 48 hours a Wardell analyst sends a written report of what it would have caught.