Analytics BIOC Informational

Access to sensitive host files from within a Kubernetes pod

A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Escape to Host (T1611)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:

Access to the host filesystem.

Investigative actions:

Look for additional suspicious activities. Verify if the exposed files were used for malicious activity. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Access to sensitive host files from within a Kubernetes pod via an interactive shell Medium (parent: Informational)
  • Unusual access to sensitive host files from within a Kubernetes pod Low (parent: Informational)