Analytics BIOC
Informational
✕
Access to sensitive host files from within a Kubernetes pod
A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Escape to Host (T1611)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:
Access to the host filesystem.
Investigative actions:
Look for additional suspicious activities. Verify if the exposed files were used for malicious activity. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Access to sensitive host files from within a Kubernetes pod via an interactive shell Medium (parent: Informational)
- Unusual access to sensitive host files from within a Kubernetes pod Low (parent: Informational)