Analytics BIOC
Informational
✕
Denied API call by a Kubernetes service account
A Kubernetes service account API call was denied.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Detector tags: Kubernetes - API
Attacker's goals:
Gain access to the Kubernetes cluster.
Investigative actions:
Check whether the service account should be making this API call. Check service account's activity, including additional executed API calls.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
2 variations:
- Denied API call by Kubernetes service account for the first time in the cluster Low (parent: Informational)
- Suspicious denied API call by a Kubernetes service account Informational