Analytics BIOC Informational

Access to kubelet credentials file

A process accessed a kubelet credentials file.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:

Impersonate the node agent to gain control over the cluster.

Investigative actions:

Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Access to kubelet credentials file by an unusual process Low (parent: Informational)