Analytics BIOC Informational

A Kubernetes cluster role was created

A Kubernetes cluster role was created.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Account Manipulation: Additional Container Cluster Roles (T1098.006)
Detector tags: Kubernetes - API
Attacker's goals:

Create overpermissive cluster roles to escalate privileges within the Kubernetes cluster.

Investigative actions:

Check the permissions granted to the newly created Kubernetes cluster role. Check whether this cluster role was bound to an identity via a ClusterRoleBinding or RoleBinding. Verify whether the identity that created the cluster role is authorized to perform RBAC operations. Review subsequent API calls made by the same identity for signs of privilege escalation or lateral movement.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Administrative Kubernetes cluster role was created for the first time Medium (parent: Informational)
  • A Kubernetes cluster role with administrative permissions was created Low (parent: Informational)
  • A Kubernetes cluster role was created for the first time by the identity Low (parent: Informational)