Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0006 ✕

Download CSV Show ATT&CK heatmap
  • Unusual Kubernetes service account file read Informational 7 variations

    An unusual process opened a Kubernetes service account file for the first time.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    7 Days
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Kubernetes - AGENT, Kubernetes Credentials Theft Analytics
    Attacker's goals: Utilize the Kubernetes service account files to perform additional actions on the cluster.
    Investigative actions: Check the exposed Kubernetes service account usage in the cluster. Check if any other suspicious activity was performed inside the pod.

    Variations

    Unusual Kubernetes service account file read within a new pod

    Informational overridden

    An unusual process opened a Kubernetes service account file for the first time. overridden

    Kubernetes service account file read

    Informational overridden

    An unusual process opened a Kubernetes service account file for the first time. overridden

    Suspicious Kubernetes service account file read from the projected volume path

    Medium overridden

    An unusual process opened a Kubernetes service account file for the first time. overridden

    Suspicious Kubernetes service account token read via an interactive shell

    Medium overridden

    An unusual process opened a Kubernetes service account file for the first time. overridden

    Suspicious Kubernetes service account token read by an unusual process

    Low overridden

    An unusual process opened the Kubernetes service account token file for the first time. overridden

    Suspicious Kubernetes service account file read by an unusual process

    Low overridden

    An unusual process opened a Kubernetes service account file for the first time. overridden

    Suspicious Kubernetes service account token read

    Low overridden

    An unusual process opened the Kubernetes service account token file for the first time. overridden