Analytics BIOC
Informational
✕
Kubernetes secrets enumeration for the first time
An identity listed Kubernetes secrets for the first time.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Container API (T1552.007)
Detector tags: Kubernetes Credentials Theft Analytics
Attacker's goals:
Enumerate secrets on a Kubernetes cluster to discover sensitive credentials.
Investigative actions:
Check if {identity_name} should have permissions to list Kubernetes secrets. The event was originated from {caller_ip} using {user_agent}. review the RBAC role bindings for {identity_name} and restrict secret listing permissions if not required. Check if {identity_name} subsequently accessed any specific secrets after the enumeration.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Kubernetes secrets enumeration across all namespaces Low (parent: Informational)