Detect Suspicious ‘exec’ Commands in kube-system Namespace

Diagram showing a command prompt with kubectl exec leading to a blue kube-system namespace node. Dashed red and blue lines indicate connections or paths, with the upwind logo at the top left.

We are excited to announce the release of a new threat detection type – exec command in a kube-system namespace. This detection alerts you that kubectl exec has run a command in your environment in the kube-system namespace, which may indicate a suspicious activity.  What is Kubectl Exec? Kubectl is a command line tool used […]