Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1552 ✕
Download CSV Show ATT&CK heatmapRetrieval of kubelet credentials Informational 1 variation
A process retrieved kubelet credentials.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)Required data: XDR AgentDetector tags: Kubernetes - AGENT, Kubernetes Credentials Theft AnalyticsAttacker's goals: Impersonate the node agent to gain control over the cluster.Investigative actions: Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.Variations
Retrieval of kubelet credentials by an unusual process
Low overridden
A process retrieved kubelet credentials. overridden