{"slug":"analyzing-kubernetes-audit-logs","source_name":"analyzing-kubernetes-audit-logs","name":"Analyzing Kubernetes Audit Logs","description":"Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns. Use when investigating Kubernetes cluster compromise or building k8s-specific SIEM detection rules.","version":1,"lift":{"pass_rate_delta_pts":4.55,"pass_rate_pct":4.5,"total_cases":22,"passed_cases":1,"tokens_delta_pct":16.6,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-07-27T23:21:33.327655+00:00"},"skill_score":0.0455,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":4.55,"with_pass_pct":4.5,"without_pass_pct":0,"tokens_delta_pct":16.6,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":22,"verdict":"mixed","never_hurt":true,"completed_at":"2026-07-27T23:21:33.327655+00:00","run_id":"a25c3549-b138-4955-8469-488f44c539ea","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":null,"content_status":"clean","indexable":true},"license":"Apache-2.0","install_count":0,"manifest_hash":"dc37eadbd8d0e1569d8bf800eff69d9d32e4ef7e9bd1749fcfc45c6164968245","raw_url":"https://app.decimal.ai/s/analyzing-kubernetes-audit-logs/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/analyzing-kubernetes-audit-logs"}