# Threat Hunting with Kubernetes Audit Logs - Part 2

DevFeed: [Threat Hunting with Kubernetes Audit Logs - Part 2](<https://devfeed.tech/articles/threat-hunting-with-kubernetes-audit-logs-part-2-15923.md>)

Original publisher: [Read original article](<https://developer.squareup.com/blog/threat-hunting-with-kubernetes-audit-logs-part-2>)

Author: Ramesh Ramani

Published: 2021-08-17T19:00:00Z

Content type: tutorial

Language: en

Sources: [Square Corner Blog RSS Feed](<https://devfeed.tech/sources/square-corner-blog-rss-feed.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [events](<https://devfeed.tech/tags/events.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [logs](<https://devfeed.tech/tags/logs.md>), [policy](<https://devfeed.tech/tags/policy.md>)

## AI overview

This tutorial explains how to use Kubernetes audit logs with the MITRE ATT&CK framework and a Kubernetes threat matrix to hunt for attackers. It develops hypotheses and example queries, including an investigation of repeated failed pod exec attempts by an anomalous user.

## Source excerpt

Using the MITRE ATT&CK® Framework to hunt for attackers