Analytics BIOC Informational

Denied API call by a Kubernetes service account

A Kubernetes service account API call was denied.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Detector tags: Kubernetes - API
Attacker's goals:

Gain access to the Kubernetes cluster.

Investigative actions:

Check whether the service account should be making this API call. Check service account's activity, including additional executed API calls.

Test period:
N/A (single event)
Deduplication:
5 Days
2 variations:
  • Denied API call by Kubernetes service account for the first time in the cluster Low (parent: Informational)
  • Suspicious denied API call by a Kubernetes service account Informational