Analytics BIOC Informational

Access to Kubernetes configuration file

A process accessed a Kubernetes node configuration file.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Kubernetes - AGENT
Attacker's goals:

Gain access to the Kubernetes environment.

Investigative actions:

Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Access to Kubernetes configuration file by an unusual process Low (parent: Informational)
  • Access to Kubernetes configuration file in a suspicious Kubernetes context Low (parent: Informational)