Analytics Informational

Kubernetes environment enumeration activity

Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Container and Resource Discovery (T1613)
Detector tags: Kubernetes - AGENT
Attacker's goals:

Map the Kubernetes cluster environment and detect potential resources to abuse.

Investigative actions:

Identify which Kubernetes resources were discovered. Investigate whether affected resources were used to extract sensitive information.

Test period:
10 Minutes
Deduplication:
5 Days
2 variations:
  • Kubernetes environment enumeration activity from a pod Medium (parent: Informational)
  • Suspicious Kubernetes environment enumeration activity Low (parent: Informational)