Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAccess to Kubernetes configuration file Informational 2 variations
A process accessed a Kubernetes node configuration file.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Kubernetes - AGENTAttacker's goals: Gain access to the Kubernetes environment.Investigative actions: Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.Variations
Access to Kubernetes configuration file by an unusual process
Low overridden
A process accessed a Kubernetes node configuration file. overridden
Access to Kubernetes configuration file in a suspicious Kubernetes context
Low overridden
A process accessed a Kubernetes node configuration file. overridden