Uploaded July 2026 | Updated September 2026, 2 weeks ago
How do you confirm a Kubernetes privilege escalation actually happened? Hunt across control plane and data plane signals in Microsoft Defender for Cloud using two tables — CloudProcessEvents for runtime activity and CloudAuditEvents for control plane actions. A quick KQL query on the audit events surfaces the creation of a cluster-admin role binding and its subject, confirming the attacker granted full admin access to the cluster.
▶ Full episode: youtu.be/CnqmC-CQs48
▶ Get started: https://aka.ms/DefenderCloudSecurity
#Shorts #DefenderForCloud #Kubernetes #ContainerSecurity #MicrosoftSecurity
How do you confirm a Kubernetes privilege escalation actually happened? Hunt across control plane and data plane signals in Microsoft Defender for Cloud using two tables — CloudProcessEvents for runtime activity and CloudAuditEvents for control plane actions. A quick KQL query on the audit events surfaces the creation of a cluster-admin role binding and its subject, confirming the attacker granted full admin access to the cluster.
▶ Full episode: youtu.be/CnqmC-CQs48
▶ Get started: https://aka.ms/DefenderCloudSecurity
#Shorts #DefenderForCloud #Kubernetes #ContainerSecurity #MicrosoftSecurity










