Analytics BIOC
Low
✕
Execution of command from within a Kubernetes pod using kubelet credentials
A command was executed from within a Kubernetes pod using Kubelet credentials. This activity allows an attacker to impersonate the node and perform privileged operations against the cluster API.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Access Token Manipulation (T1134)
Detector tags: Kubernetes - AGENT
Attacker's goals:
Usage of the Kubernetes API server to perform operations inside the cluster.
Investigative actions:
Check if there is an active attack against the Kubernetes cluster.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unusual execution of command from within a Kubernetes pod using kubelet credentials Medium (parent: Low)