drop gke audit log · parse api + admin events
flags workload identity anomalies · master authorized networks changes · binary authorization bypass · admin bursts
heuristic screener · export schema varies by sink — filters GKE/container API activity only · not definitive proof