Analytics BIOC Informational

Kubernetes secrets enumeration for the first time

An identity listed Kubernetes secrets for the first time.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Container API (T1552.007)
Detector tags: Kubernetes Credentials Theft Analytics
Attacker's goals:

Enumerate secrets on a Kubernetes cluster to discover sensitive credentials.

Investigative actions:

Check if {identity_name} should have permissions to list Kubernetes secrets. The event was originated from {caller_ip} using {user_agent}. review the RBAC role bindings for {identity_name} and restrict secret listing permissions if not required. Check if {identity_name} subsequently accessed any specific secrets after the enumeration.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Kubernetes secrets enumeration across all namespaces Low (parent: Informational)