Analytics BIOC
Informational
✕
Access to kubelet credentials file
A process accessed a kubelet credentials file.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:
Impersonate the node agent to gain control over the cluster.
Investigative actions:
Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Access to kubelet credentials file by an unusual process Low (parent: Informational)