資安週報Security Weekly 攻擊手法通報 × 資安工具Advisories × Tooling
網路可視性Network visibility Apache-2.0

Kubeshark

Kubernetes 叢集的即時流量檢視器,以 eBPF 擷取並帶上完整的 K8s 脈絡——等於叢集版的 Wireshark。Real-time traffic visibility for Kubernetes, capturing with eBPF and annotating with full K8s context — Wireshark for your cluster.

這是什麼What it is

容器環境最大的偵測盲區是東西向流量:pod 對 pod 的呼叫全在叢集內部,傳統的邊界監控完全看不到。出事時你想知道「這個服務到底連了哪裡」,卻只能翻應用程式日誌拼湊。

Kubeshark 以 eBPF 在節點上擷取流量,解析 L4/L7 協定(HTTP、gRPC、Kafka、Redis、DNS 等),並把每一筆都標上來源與目的的 pod、service、namespace。不需要改動應用程式、不需要 sidecar。它也能在不持有金鑰的情況下解密叢集內的 TLS 流量,因為擷取點在加密發生之前。

對資安而言,它填補的是橫向移動階段的觀測缺口——攻擊者在叢集內的探測與擴散,在這裡看得見。

The biggest detection blind spot in container environments is east-west traffic: pod-to-pod calls stay inside the cluster, invisible to perimeter monitoring. When something goes wrong and you need to know what a service actually connected to, you are left reconstructing it from application logs.

Kubeshark captures with eBPF on the node, parses L4/L7 protocols (HTTP, gRPC, Kafka, Redis, DNS, and more), and annotates every record with source and destination pod, service, and namespace. No application changes, no sidecars. It can also read in-cluster TLS traffic without holding keys, because capture happens before encryption.

For security, it fills the observability gap during lateral movement — an attacker probing and spreading inside the cluster becomes visible.

什麼時候用得上When to use it

- 事件調查:確認某個 pod 遭入侵後對外與對內連了哪些位址,是釐清影響範圍最直接的方式
- 驗證網路政策:你以為 NetworkPolicy 擋住的連線,實際上真的擋住了嗎?直接看流量
- 找出非預期的外連:容器映像裡夾帶的惡意套件會對外通訊,這裡看得到
- 除錯:服務之間為什麼呼叫失敗,看實際封包比看日誌快

可用查詢語法過濾特定條件,也支援設定規則在符合條件時告警。

- Incident investigation: after a pod is compromised, see exactly what it reached internally and externally — the most direct way to scope impact
- Validate network policy: is that NetworkPolicy actually blocking what you think? Look at the traffic
- Spot unexpected egress: a malicious package baked into an image will phone home, and it shows up here
- Debugging: when service calls fail, packets answer faster than logs

A query language filters for specific conditions, and rules can raise alerts on matches.

注意事項Caveats

它會看到流經叢集的所有內容,包含請求中的個資與憑證——部署前要先想清楚存取控制與保存期限,否則你等於建立了一個新的敏感資料集中點。生產環境部署前也要評估 eBPF 擷取對節點效能的影響,並先在測試叢集驗證。

It sees everything crossing the cluster, including PII and credentials inside requests — settle access control and retention before deploying, or you have created a new concentration of sensitive data. Assess the node performance cost of eBPF capture before production, and validate on a test cluster first.

安裝Install

brew install kubeshark
# 或 / or
sh <(curl -Ls https://kubeshark.co/install)

快速上手Quick start

# 在目前的 kubectl context 上啟動,開啟本機儀表板
kubeshark tap

# 只擷取特定 namespace
kubeshark tap -n production

# 用查詢語法過濾:非 2xx 的 HTTP 回應
# (於儀表板查詢列輸入)
# http and response.status != 200

出現在Featured in