Hunt Kubernetes Privilege Escalation With KQL @MSFTMechanics
Hunt Kubernetes Privilege Escalation With KQL  @MSFTMechanics
Uploaded July 2026 | Updated September 2026, 2 weeks ago
How do you confirm a Kubernetes privilege escalation actually happened? Hunt across control plane and data plane signals in Microsoft Defender for Cloud using two tables — CloudProcessEvents for runtime activity and CloudAuditEvents for control plane actions. A quick KQL query on the audit events surfaces the creation of a cluster-admin role binding and its subject, confirming the attacker granted full admin access to the cluster.

▶ Full episode: youtu.be/CnqmC-CQs48
▶ Get started: https://aka.ms/DefenderCloudSecurity

#Shorts #DefenderForCloud #Kubernetes #ContainerSecurity #MicrosoftSecurity
Hunt Kubernetes Privilege Escalation With KQLNo more copy/paste into unmanaged AI sites. #MicrosoftCopilot #Microsoft365 #CopilotCowork #AIAgentsBuild a Power App in Under a MinuteMap risky agent actions in one view. #cybersecurity #AIAgents #MicrosoftPurview #DataSecurityCross cloud context in one view. #DefenderForCloud #ContainerSecurity #MicrosoftSecurity #KubernetesAuto-trust every app you deploy. #MicrosoftIntune #Intune #EndpointManagement #Microsoft365Data Security Investigations in Microsoft PurviewExtend Work IQ to non-Microsoft systems. #MicrosoftCopilot #Microsoft365 #AIAgents #CopilotNo Windows 365 On My Phone. Still Works.Build Agent Architecture using AI Landing ZonesType One Sentence, Get a Full Year of DataNew agentic platform in Dynamics 365 for Sales and Service
Microsoft Mechanics |

Hunt Kubernetes Privilege Escalation With KQL

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER