Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Suspicious access to Kubernetes API with kubelet credentials Low Cloud 1 variation

    A combination of signals has been detected indicating that kubelet credentials were used inside a pod to access the Kubernetes API. This activity suggests an attempt to escalate privileges or move laterally within the cluster.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Exfiltration (TA0010) Collection (TA0009)
    ATT&CK techniques: Data from Cloud Storage (T1530) Automated Exfiltration (T1020)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Cloud Data Asset Exfiltration, Data Detection & Response
    Attacker's goals: Usage of the Kubernetes API server to perform operations inside the cluster.
    Investigative actions: Check if there is an active attack against the Kubernetes cluster.

    Variations

    Suspicious access to Kubernetes API with kubelet credentials from unusual pod

    Medium overridden

    A combination of signals has been detected indicating that kubelet credentials were used inside a pod to access the Kubernetes API. This activity suggests an attempt to escalate privileges or move laterally within the cluster. overridden