Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1552 ✕
Download CSV Show ATT&CK heatmapUnusual Kubernetes service account file read Informational 7 variations
An unusual process opened a Kubernetes service account file for the first time.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 7 Days
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Kubernetes - AGENT, Kubernetes Credentials Theft AnalyticsAttacker's goals: Utilize the Kubernetes service account files to perform additional actions on the cluster.Investigative actions: Check the exposed Kubernetes service account usage in the cluster. Check if any other suspicious activity was performed inside the pod.Variations
Unusual Kubernetes service account file read within a new pod
Informational overridden
An unusual process opened a Kubernetes service account file for the first time. overridden
Kubernetes service account file read
Informational overridden
An unusual process opened a Kubernetes service account file for the first time. overridden
Suspicious Kubernetes service account file read from the projected volume path
Medium overridden
An unusual process opened a Kubernetes service account file for the first time. overridden
Suspicious Kubernetes service account token read via an interactive shell
Medium overridden
An unusual process opened a Kubernetes service account file for the first time. overridden
Suspicious Kubernetes service account token read by an unusual process
Low overridden
An unusual process opened the Kubernetes service account token file for the first time. overridden
Suspicious Kubernetes service account file read by an unusual process
Low overridden
An unusual process opened a Kubernetes service account file for the first time. overridden
Suspicious Kubernetes service account token read
Low overridden
An unusual process opened the Kubernetes service account token file for the first time. overridden