Analytics BIOC
Informational
✕
Access to Kubernetes CA certificate file
A process accessed a Kubernetes CA certificate file.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:
Make API calls against the Kubernetes cluster.
Investigative actions:
Look for additional suspicious activities. Verify if the exposed certificate was used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed certificate.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Access to Kubernetes CA certificate file by an unusual process Low (parent: Informational)