Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1610 ✕
Download CSV Show ATT&CK heatmapKubernetes vulnerability scanning tool usage Medium Cloud 2 variations
A known vulnerability scanning tool was used within a Kubernetes cluster.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Execution (TA0002) Discovery (TA0007)ATT&CK techniques: Deploy Container (T1610) Container and Resource Discovery (T1613)Required data: AWS Audit Log Azure Audit Log Gcp Audit Log Kubernetes Audit LogsDetector tags: Kubernetes - APIAttacker's goals: Usage of known tools and frameworks to exploit Kubernetes clusters.Investigative actions: Check if this activity is expected (e.g. penetration testing). Determine which Kubernetes resources were affected. Review additional events for any suspicious activity within the cluster.Variations
Kubernetes vulnerability scanning tool usage within a pod
Medium overridden
A known vulnerability scanning tool was used from a pod within a Kubernetes cluster. overridden
External Kubernetes vulnerability scanning tool usage
Medium overridden
A known vulnerability scanning tool was used within a Kubernetes clusteroutside the cloud environment. overridden