Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1613 ✕
Download CSV Show ATT&CK heatmapKubernetes environment enumeration activity Informational 2 variations
Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 10 Minutes
- Deduplication:
- 5 Days
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Container and Resource Discovery (T1613)Required data: XDR AgentDetector tags: Kubernetes - AGENTAttacker's goals: Map the Kubernetes cluster environment and detect potential resources to abuse.Investigative actions: Identify which Kubernetes resources were discovered. Investigate whether affected resources were used to extract sensitive information.Variations
Kubernetes environment enumeration activity from a pod
Medium overridden
Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. overridden
Suspicious Kubernetes environment enumeration activity
Low overridden
Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. overridden