drop k8s audit log · detect sa token usage from unexpected pods
flags unusual token review userAgent · cross-namespace service account usage · per-file try/catch
heuristic screener · audit schema varies by cluster version — field mapping is best-effort · not definitive proof