Analytics BIOC Informational

Access to Kubernetes CA certificate file

A process accessed a Kubernetes CA certificate file.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:

Make API calls against the Kubernetes cluster.

Investigative actions:

Look for additional suspicious activities. Verify if the exposed certificate was used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed certificate.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Access to Kubernetes CA certificate file by an unusual process Low (parent: Informational)