Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕ technique: T1552 ✕
Download CSV Show ATT&CK heatmapKubernetes secrets enumeration for the first time Informational Cloud 1 variation
An identity listed Kubernetes secrets for the first time.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials: Container API (T1552.007)Required data: AWS Audit Log Azure Audit Log Gcp Audit Log Kubernetes Audit LogsDetector tags: Kubernetes Credentials Theft AnalyticsAttacker's goals: Enumerate secrets on a Kubernetes cluster to discover sensitive credentials.Investigative actions: Check if {identity_name} should have permissions to list Kubernetes secrets. The event was originated from {caller_ip} using {user_agent}. review the RBAC role bindings for {identity_name} and restrict secret listing permissions if not required. Check if {identity_name} subsequently accessed any specific secrets after the enumeration.Variations
Kubernetes secrets enumeration across all namespaces
Low overridden
An identity listed Kubernetes secrets for the first time. overridden