Skip to content

Commit 60acc97

Browse files
authored
Merge pull request #717 from p-rog/ztvp-blogs
blog: Add ACS runtime threat response article reference
2 parents 6f0b1c8 + aadf74d commit 60acc97

1 file changed

Lines changed: 55 additions & 0 deletions

File tree

Lines changed: 55 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,55 @@
1+
---
2+
date: 2026-07-29
3+
title: "Lights On! Real-Time Threat Response with Red Hat Advanced Cluster Security"
4+
summary: When network policies trap an attacker inside a container, what happens next? The ZTVP turns Red Hat Advanced Cluster Security into an active defense engine that detects anomalous behavior and terminates compromised pods in real time.
5+
author: Przemyslaw Roguski
6+
blog_tags:
7+
- patterns
8+
- zero-trust
9+
- security
10+
- acs
11+
- runtime-security
12+
- openshift
13+
---
14+
:toc:
15+
:imagesdir: /images
16+
17+
== From gates to guards
18+
19+
In the https://validatedpatterns.io/blog/2026-06-29-zero-trust-network-policies/[first article of this series], we locked every door: default-deny network policies block lateral movement and data exfiltration even when a vulnerability is exploited faster than you can patch.
20+
21+
But locking doors only works if someone is watching what happens inside the room. A true zero trust architecture — as defined by https://csrc.nist.gov/pubs/sp/800/207/final[NIST SP 800-207] — demands continuous runtime verification, not just static access controls.
22+
23+
== ACS as the zero trust brain
24+
25+
The https://validatedpatterns.io/patterns/layered-zero-trust/[Layered Zero Trust Validated Pattern] deploys Red Hat Advanced Cluster Security with four custom security policies that go far beyond the default configuration. These policies are split into two operational categories:
26+
27+
*Deploy-time alerting* — catches missing network boundaries before they reach production:
28+
29+
* Alerts when a deployment lacks an *ingress* NetworkPolicy
30+
* Alerts when a deployment lacks an *egress* NetworkPolicy
31+
32+
*Runtime termination* — neutralizes active threats in real time:
33+
34+
* *Privilege escalation prevention* — instantly kills any pod that attempts `sudo`, `su`, `pkexec`, `nsenter`, or `unshare`
35+
* *Suspicious exec termination* — immediately terminates pods running reconnaissance tools like `nmap`, `nc`, or `ncat`
36+
37+
The result: network policies block the attacker's escape routes, and ACS eliminates the threat entirely — even if a configuration was missed.
38+
39+
== See it in action
40+
41+
The article includes a video demonstration of the "assume a breach" scenario. An attacker who has gained code execution inside a pod attempts to run reconnaissance commands. Within seconds, ACS detects the anomalous behavior and terminates the pod — no human intervention required.
42+
43+
== Read the full article
44+
45+
For the complete deep dive into how ZTVP implements the NIST 800-207 control loop with ACS as the policy decision and enforcement engine, read the full article on the Red Hat blog:
46+
47+
**https://www.redhat.com/en/blog/lights-real-time-threat-response-red-hat-advanced-cluster-security[Lights On! Real-Time Threat Response with Red Hat Advanced Cluster Security]**
48+
49+
== Get started
50+
51+
The Layered Zero Trust Validated Pattern is open source:
52+
53+
* https://validatedpatterns.io/patterns/layered-zero-trust/[Pattern documentation]
54+
* https://github.com/validatedpatterns/layered-zero-trust[Source repository]
55+

0 commit comments

Comments
 (0)