Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Access to Kubernetes configuration file Informational 2 variations

    A process accessed a Kubernetes node configuration file.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Kubernetes - AGENT
    Attacker's goals: Gain access to the Kubernetes environment.
    Investigative actions: Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.

    Variations

    Access to Kubernetes configuration file by an unusual process

    Low overridden

    A process accessed a Kubernetes node configuration file. overridden

    Access to Kubernetes configuration file in a suspicious Kubernetes context

    Low overridden

    A process accessed a Kubernetes node configuration file. overridden