M ManySignal
MS
K8
Integration

Kubernetes Integration

Container runtime and RBAC threat detection across your Kubernetes clusters.

What this integration does

Kubernetes meets agentic SOC

Kubernetes is the dominant container orchestration platform, introducing unique attack surfaces: RBAC misconfiguration, container escape, privileged pod abuse, and supply chain injection into CI/CD pipelines. ManySignal ingests Kubernetes Audit Logs, runtime events, and RBAC policy changes to detect threats across your container infrastructure.

Kubernetes Audit Log ingestion for API server events

RBAC privilege escalation detection (ClusterRole binding creation)

Privileged pod and hostPath mount detection

Data collected

  • Kubernetes API server audit log events
  • RBAC resource create/modify events
  • Pod and workload lifecycle events
  • Falco runtime alerts (if Falco is deployed)
  • Namespace and cluster-wide policy changes

Actions supported

  • Delete suspicious pod
  • Patch RBAC binding to remove excessive permissions
  • Quarantine namespace (apply network policy to isolate)
  • Cordon node to prevent new pod scheduling

Getting started

Set up in minutes

  1. 1

    Configure audit log shipping

  2. 2

    Deploy ManySignal's Kubernetes agent (optional)

  3. 3

    Configure RBAC permissions

Kubernetes Integration: frequently asked questions

Does ManySignal work with managed Kubernetes (EKS, GKE, AKS)?

Yes. Each managed Kubernetes provider has a different audit log delivery mechanism. EKS delivers to CloudWatch Logs, GKE to Cloud Audit Logs, and AKS to Azure Monitor — ManySignal reads from each source natively.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.