Kubernetes Integration
Container runtime and RBAC threat detection across your Kubernetes clusters.
What this integration does
Kubernetes meets agentic SOC
Kubernetes is the dominant container orchestration platform, introducing unique attack surfaces: RBAC misconfiguration, container escape, privileged pod abuse, and supply chain injection into CI/CD pipelines. ManySignal ingests Kubernetes Audit Logs, runtime events, and RBAC policy changes to detect threats across your container infrastructure.
Kubernetes Audit Log ingestion for API server events
RBAC privilege escalation detection (ClusterRole binding creation)
Privileged pod and hostPath mount detection
Data collected
- Kubernetes API server audit log events
- RBAC resource create/modify events
- Pod and workload lifecycle events
- Falco runtime alerts (if Falco is deployed)
- Namespace and cluster-wide policy changes
Actions supported
- Delete suspicious pod
- Patch RBAC binding to remove excessive permissions
- Quarantine namespace (apply network policy to isolate)
- Cordon node to prevent new pod scheduling
Getting started
Set up in minutes
- 1
Configure audit log shipping
- 2
Deploy ManySignal's Kubernetes agent (optional)
- 3
Configure RBAC permissions
Kubernetes Integration: frequently asked questions
Does ManySignal work with managed Kubernetes (EKS, GKE, AKS)?
Yes. Each managed Kubernetes provider has a different audit log delivery mechanism. EKS delivers to CloudWatch Logs, GKE to Cloud Audit Logs, and AKS to Azure Monitor — ManySignal reads from each source natively.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.