Analytics BIOC
Informational
✕
A Kubernetes service account executed an unusual API call
A Kubernetes service account executed an unusual API call.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Detector tags: Kubernetes - API
Attacker's goals:
Abuse a service account token to gain access to the Kubernetes cluster.
Investigative actions:
Verify whether the service account should be executing this API. Investigate other operations that were performed by the service account within the cluster.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
4 variations:
- A Kubernetes service account executed an API call on a first-seen resource Low (parent: Informational)
- A Kubernetes service account executed an API call on an unusual sensitive resource Low (parent: Informational)
- A Kubernetes service account executed an unusual modification API call Informational
- A Kubernetes service account executed an API call on an unusual resource Informational