The Secure Way
Runtime detection and observability, the secure way
Tetragon, alerting as code, multi-tenant logs and knowing when a sensor goes quiet.
11 guides
- Alerting when a sensor goes quiet, the secure wayAlert when a security sensor stops reporting: a target that is down, a target that vanished, an agent that is up but silent, and a host far quieter than its peers.
- Detecting sign-in brute force from logs, the secure wayThree LogQL detections for SSH sign-in attacks (brute force, password spraying, and a success after failures) as Loki ruler alerts, tested on synthetic logs.
- Kubescape CIS, NSA and MITRE scans, the secure wayScan Kubernetes manifests with Kubescape against the NSA and MITRE frameworks in CI, gate merges on a compliance threshold, and run CIS checks on the cluster.
- Loki multi-tenancy, the secure wayRun Loki with auth_enabled and put an authenticating gateway in front that sets X-Scope-OrgID itself, because Loki trusts whatever header it receives. Tested.
- Multi-tenant OTLP ingest with Alloy, the secure wayAccept OTLP logs from several tenants with Grafana Alloy: TLS, one credential set per tenant, and a tenant ID set by the pipeline instead of the client. Tested.
- Security alerting as code in Grafana, the secure wayProvision Grafana security alert rules, contact points and routing from files in git, so nobody can quietly edit or delete a detection in the UI. Tested end to end.
- Tetragon egress monitoring for CI, the secure waySee every outbound connection a CI build pod makes, and which process made it, with a namespaced Tetragon tcp_connect policy; kill unexpected egress.
- Tetragon runtime detection on Talos, the secure wayInstall Tetragon on Talos Linux with the tracing mount it needs, keep host and kube-system events in the export, redact secrets, and keep gRPC off the network.
- Tetragon: catching privilege escalation, the secure wayDetect privilege escalation inside Kubernetes pods with Tetragon: setuid calls to root and new credentials from commit_creds, plus Sigkill enforcement.
- Tetragon: credential file reads, the secure wayDetect reads of /etc/shadow, SSH keys and Kubernetes service account tokens with a Tetragon policy on security_file_permission, filtered in the kernel.
- Tetragon: kernel module and BPF loads, the secure wayDetect kernel module loads, automatic module requests and BPF program loads with Tetragon policies, the moves rootkits and eBPF-based malware make to hide on a node.
T Academy
Every guide here is taught hands-on in H2-CTDE Runtime Detection and Response: a real host in your browser, and every objective checked on the machine.
Start free