Analytics BIOC
Informational
✕
Kubernetes admission controller activity
A Kubernetes admission controller has been created or modified.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Persistence (TA0003) Credential Access (TA0006)
ATT&CK techniques: Valid Accounts (T1078) Unsecured Credentials: Container API (T1552.007)
Detector tags: Kubernetes - API
Attacker's goals:
Intercept the requests to the Kubernetes API sever, records secrets, and other sensitive information. Modify requests to the Kubernetes API sever.
Investigative actions:
Verify whether the identity should use Kubernetes admission controllers. Examine the role of the Kubernetes admission controller and its intended function. Investigate other operations that were performed by the identity within the cluster.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
4 variations:
- Kubernetes validating admission controller was used in the organization for the first time Low (parent: Informational)
- Kubernetes mutating admission controller was used in the organization for the first time Medium (parent: Informational)
- Kubernetes validating admission controller was used in the cluster for the first time Low (parent: Informational)
- Kubernetes mutating admission controller was used in the cluster for the first time Medium (parent: Informational)