Analytics High

An unusual process in ingress-nginx has accessed a service-account token file

An unusual process in ingress-nginx has read a service-account token.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006)
ATT&CK techniques: Exploit Public-Facing Application (T1190) Unsecured Credentials (T1552)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

An attacker is attempting to gain unauthorized access by leveraging valid credentials.

Investigative actions:

Check if the process is intended to preform these actions.

Test period:
1 Hour
Deduplication:
1 Day