Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1204 ✕

Download CSV Show ATT&CK heatmap
  • A Kubernetes service account executed an unusual API call Informational Cloud 4 variations

    A Kubernetes service account executed an unusual API call.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log Kubernetes Audit Logs
    Detector tags: Kubernetes - API
    Attacker's goals: Abuse a service account token to gain access to the Kubernetes cluster.
    Investigative actions: Verify whether the service account should be executing this API. Investigate other operations that were performed by the service account within the cluster.

    Variations

    A Kubernetes service account executed an API call on a first-seen resource

    Low overridden

    A Kubernetes service account executed an API call on a first-seen resource. overridden

    A Kubernetes service account executed an API call on an unusual sensitive resource

    Low overridden

    A Kubernetes service account executed an API call on an unusual sensitive resource. overridden

    A Kubernetes service account executed an unusual modification API call

    Informational overridden

    A Kubernetes service account executed an unusual modification API call. overridden

    A Kubernetes service account executed an API call on an unusual resource

    Informational overridden

    A Kubernetes service account executed an API call on an unusual resource. overridden