bykillvxk· 108 skills
解析 Kubernetes API server 审计日志(JSON lines 格式),检测 exec 进入 Pod、 Secret 访问、RBAC 修改、特权 Pod 创建以及匿名 API 访问行为。 从审计事件模式构建威胁检测规则。适用于调查 Kubernetes 集群入侵 或构建 k8s 专用 SIEM 检测规则。
$npx -y skills add killvxk/cybersecurity-skills-zh --skill analyzing-kubernetes-audit-logsInstalls into the current project.
Run `npx skills use "https://github.com/killvxk/cybersecurity-skills-zh" --skill "killvxk/cybersecurity-skills-zh/analyzing-kubernetes-audit-logs"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/killvxk/cybersecurity-skills-zh" that are relevant to the current task. Run `npx skills add "https://github.com/killvxk/cybersecurity-skills-zh"` and select the relevant skills, then follow their instructions.