Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0001 ✕

Download CSV Show ATT&CK heatmap
  • Kubernetes service account activity outside the cluster Informational Cloud 2 variations

    A service account user successfully invoked API calls outside the Kubernetes cluster.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Default Accounts (T1078.001)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log Kubernetes Audit Logs
    Detector tags: Kubernetes - API
    Attacker's goals: Gain access to the Kubernetes cluster.
    Investigative actions: Determine which Kubernetes resources were accessed using the service account. Verify whether the service account token was exposed.

    Variations

    Unusual Kubernetes service account activity outside the cluster

    Low overridden

    A service account user successfully invoked API calls outside the Kubernetes cluster. overridden

    Kubernetes service account activity outside the cluster from non-cloud IP

    Low overridden

    A service account user successfully invoked API calls outside the Kubernetes cluster. overridden