Skip to content

Project 07 — Kubernetes SOC Integration

Welcome to Project 07 — Kubernetes SOC Integration.

In this capstone project, you will act as a:

  • Kubernetes Security Engineer
  • Cloud SOC Engineer
  • Detection Engineer
  • SIEM Engineer
  • Security Automation Engineer
  • Incident Response Engineer

Your mission is to integrate Kubernetes security telemetry into an enterprise Security Operations Centre (SOC).

Unlike previous projects that focused on individual security controls, this project combines prevention, detection, investigation, response and automation into one enterprise SOC architecture.

This is how modern organizations monitor Kubernetes production environments 24×7.

Amazon EKS
Security Telemetry
Central Log Collection
SIEM Correlation
Threat Detection
SOAR Automation
SOC Investigation
Incident Response
Lessons Learned

CloudNova Technologies has successfully secured its Kubernetes platform.

The next objective is to integrate Kubernetes into the Enterprise SOC.

The organization requires:

  • Continuous monitoring
  • Centralized logging
  • Threat correlation
  • Automated alerting
  • Security dashboards
  • SOAR automation
  • Incident response
  • Executive reporting

Your task is to design, deploy and validate the complete Kubernetes SOC monitoring platform.


CloudNova Technologies operates:

  • Multiple Amazon EKS clusters
  • Multiple AWS Accounts
  • Multi-region deployments
  • Hundreds of namespaces
  • Thousands of Pods

Their SOC currently monitors:

  • Windows Servers
  • Linux Servers
  • Firewalls
  • Active Directory
  • AWS CloudTrail
  • Network Security
  • Email Security

However, Kubernetes is not fully integrated into their SOC.

As a result:

  • Runtime attacks may be missed
  • Kubernetes attacks are difficult to correlate
  • Pod compromise is difficult to investigate
  • Alerts lack Kubernetes context
  • Incident response is inconsistent

Management has requested a centralized Kubernetes SOC platform.


CloudNova Technologies should receive:

  • Enterprise Kubernetes SOC Architecture
  • Centralized SIEM Integration
  • Runtime Threat Detection
  • Cloud Detection Correlation
  • SOAR Automation
  • Kubernetes Detection Rules
  • Threat Hunting Playbooks
  • Incident Response Workflows
  • Executive Dashboards
  • Production Readiness Documentation

By completing this project you will learn how to:

  • Design Kubernetes SOC Architecture
  • Centralize Kubernetes Security Logs
  • Build SIEM Detection Rules
  • Create Threat Hunting Queries
  • Correlate CloudTrail with Kubernetes
  • Correlate Runtime Events
  • Build SOC Dashboards
  • Create SOAR Playbooks
  • Automate Incident Response
  • Validate Detection Engineering
  • Produce Executive Security Reports

Level: Expert


16–24 Hours


  • Enterprise SOC Project
  • SIEM Integration
  • Detection Engineering
  • Threat Hunting
  • Incident Response
  • SOAR Automation
  • Executive Reporting
  • Portfolio Project

  • Amazon EKS
  • AWS CloudTrail
  • CloudWatch Logs
  • Kubernetes Audit Logs
  • Amazon GuardDuty
  • Amazon Security Hub
  • Amazon Detective
  • AWS Config
  • Falco
  • Falcosidekick
  • Prometheus
  • Grafana
  • EventBridge
  • SNS
  • Lambda
  • Splunk / Microsoft Sentinel / Elastic / QRadar
  • Shuffle SOAR / Cortex XSOAR / Tines
  • Jira
  • Slack
  • Terraform
  • kubectl

Amazon EKS Clusters
Kubernetes Audit Logs
CloudWatch Logs
CloudTrail
Falco
GuardDuty Runtime Monitoring
Security Hub
EventBridge
SIEM
SOAR
SOC Analysts
Incident Response
Executive Reporting

The SOC should collect:

  • Audit Logs
  • API Activity
  • Pod Events
  • Namespace Events
  • RBAC Changes
  • Secret Access
  • ConfigMap Changes
  • Admission Controller Logs

  • Falco Events
  • Process Execution
  • File Access
  • Runtime Socket Access
  • Reverse Shells
  • Cryptomining
  • Privilege Escalation

  • CloudTrail
  • GuardDuty
  • Inspector
  • Security Hub
  • AWS Config
  • VPC Flow Logs
  • Route53 Resolver Logs

  • Prometheus Alerts
  • Grafana Alerts
  • Node Logs
  • Container Runtime Logs

  • SOC Architecture
  • Detection Pipeline
  • SIEM Architecture
  • SOAR Workflow
  • Alert Routing
  • Dashboard Design

  • Detection Catalogue
  • Correlation Rules
  • MITRE ATT&CK Mapping
  • Severity Matrix
  • Threat Hunting Queries

  • SOC Runbooks
  • SOAR Playbooks
  • Escalation Matrix
  • Investigation Guides

  • Security Dashboard
  • KPI Dashboard
  • SOC Metrics
  • Incident Metrics
  • Maturity Report

07-kubernetes-soc-integration/
├── README.md
├── 01-requirements/
├── 02-architecture/
├── 03-log-sources/
├── 04-siem/
├── 05-detection-engineering/
├── 06-threat-hunting/
├── 07-soar/
├── 08-dashboards/
├── 09-runbooks/
├── 10-playbooks/
├── 11-testing/
├── 12-findings/
├── 13-report/
└── 14-presentations/

Phase 1 — Requirements
Phase 2 — SOC Architecture
Phase 3 — Security Telemetry
Phase 4 — SIEM Integration
Phase 5 — Detection Engineering
Phase 6 — Threat Hunting
Phase 7 — SOAR Automation
Phase 8 — Dashboards
Phase 9 — Incident Response
Phase 10 — Validation
Phase 11 — Executive Reporting

Document:

  • Business Objectives
  • SOC Scope
  • AWS Accounts
  • Kubernetes Clusters
  • Critical Applications
  • Log Sources
  • Compliance Requirements
  • Incident Severity Matrix

Design:

AWS
CloudTrail
CloudWatch
Security Hub
EventBridge
SIEM
SOAR
SOC

Include:

  • Multi-account logging
  • Cross-region logging
  • High availability
  • Log retention
  • Data encryption

Collect:

  • Kubernetes Audit Logs
  • Falco Events
  • GuardDuty Findings
  • CloudTrail Events
  • IAM Events
  • Pod Lifecycle Events
  • Admission Controller Logs
  • Node Events

Validate:

Terminal window
kubectl get events -A

Normalize logs into a common schema.

Fields:

Field Example
Cluster production-eks
Namespace payments
Pod payment-api
Container api
User admin@example.com
ServiceAccount payment-api
Node ip-10-0-1-15
Severity High

Create parsers for:

  • Audit Logs
  • Falco
  • GuardDuty
  • CloudTrail

Build detections for:

  • Privileged Pod Deployment
  • ClusterRoleBinding Creation
  • Secret Enumeration
  • Service Account Abuse
  • Pod Exec
  • HostPath Mount
  • Runtime Socket Access
  • Reverse Shell
  • Suspicious Process
  • Cryptomining
  • Node Compromise
  • Lateral Movement

Map every detection to MITRE ATT&CK.


Develop hunting queries for:

  • Excessive Secret Reads
  • Failed Authentication
  • New Cluster Admins
  • Suspicious Exec Sessions
  • Anonymous API Requests
  • Runtime Socket Access
  • Privileged Containers
  • HostPath Volumes
  • High CPU Pods
  • External Network Connections

Produce:

  • Hunting Guide
  • Query Library
  • Investigation Notes

Automate:

Critical Alert
Create Incident
Notify Slack
Notify SOC
Run Investigation
Optional Containment
Collect Evidence
Assign Analyst

Automations may include:

  • Create Jira ticket
  • Send Teams/Slack notification
  • Tag Security Hub finding
  • Attach runbook
  • Collect Pod logs
  • Capture Kubernetes events
  • Export CloudTrail evidence

Create dashboards for:

  • Open Incidents
  • Critical Alerts
  • Compliance Status
  • Mean Time To Detect
  • Mean Time To Respond

  • Alerts by Cluster
  • Alerts by Namespace
  • Falco Events
  • GuardDuty Findings
  • Runtime Alerts
  • Top Threats
  • MITRE Mapping

  • Node Health
  • Runtime Coverage
  • Agent Health
  • Logging Pipeline
  • SIEM Latency

Create runbooks for:

  • Compromised Pod
  • Container Escape
  • Privileged Container
  • Secret Exposure
  • Runtime Malware
  • Node Compromise
  • RBAC Abuse
  • Kubernetes API Attack

Every runbook should include:

  • Identification
  • Validation
  • Containment
  • Eradication
  • Recovery
  • Lessons Learned

Perform safe testing.

Validate:

  • Audit Logs
  • Falco Alerts
  • GuardDuty Findings
  • SIEM Parsing
  • SOAR Automation
  • Dashboard Updates
  • Notification Delivery

Create evidence for every validation.


Produce:

Business impact of Kubernetes threats.


  • MTTD
  • MTTR
  • False Positives
  • Runtime Coverage
  • Detection Success Rate

KPI Target
Audit Logging 100%
Runtime Coverage 100%
Critical Alert Delivery <60 sec
SIEM Availability 99.9%
False Positive Rate <5%

Map detections to:

  • Initial Access
  • Execution
  • Persistence
  • Privilege Escalation
  • Defense Evasion
  • Credential Access
  • Discovery
  • Lateral Movement
  • Collection
  • Exfiltration
  • Impact

Create reusable hunts for:

  • Suspicious Service Accounts
  • Long-running Exec Sessions
  • Newly Created Privileged Pods
  • Failed API Authentication
  • Unexpected Namespace Creation
  • Container Runtime Abuse
  • Host Filesystem Access
  • Reverse Shell Activity

  • Audit Logs enabled
  • CloudTrail centralized
  • GuardDuty enabled
  • Security Hub integrated
  • Falco deployed
  • Runtime coverage validated
  • SIEM integrated
  • SOAR operational
  • Dashboards created
  • Runbooks documented
  • Threat hunting queries tested
  • Detection engineering validated
  • Executive reports completed

Track:

  • Mean Time To Detect (MTTD)
  • Mean Time To Respond (MTTR)
  • Runtime Detection Coverage
  • Detection Accuracy
  • Alert Volume
  • Critical Incident Count
  • Investigation Time
  • False Positive Rate
  • Automation Success Rate

1. Why should Kubernetes telemetry be integrated into a SOC?

Section titled “1. Why should Kubernetes telemetry be integrated into a SOC?”

Answer: Centralized monitoring enables security teams to correlate Kubernetes events with cloud, identity and network telemetry, improving detection, investigation and response.

Answer: A common event schema enables accurate correlation, searching and reporting across different log sources.

3. Why should MITRE ATT&CK mapping be used?

Section titled “3. Why should MITRE ATT&CK mapping be used?”

Answer: MITRE ATT&CK helps security teams understand attacker techniques, identify detection gaps and communicate coverage consistently.

Answer: SOAR automates repetitive response tasks, accelerates investigations and ensures consistent handling of security incidents.

5. Why should threat hunting complement automated detections?

Section titled “5. Why should threat hunting complement automated detections?”

Answer: Automated rules detect known behaviors, while threat hunting proactively searches for unknown, stealthy or emerging threats that may not yet trigger existing detections.


By completing this project you will demonstrate the ability to:

  • Build an enterprise Kubernetes SOC architecture
  • Integrate Kubernetes with a SIEM and SOAR platform
  • Engineer Kubernetes detection rules
  • Develop threat hunting content
  • Correlate cloud-native security telemetry
  • Create executive and operational security dashboards
  • Build enterprise-grade incident response workflows
  • Operate Kubernetes security at SOC scale

➡️ Next Project: Project 08 — Enterprise Kubernetes Zero Trust Security Platform