Analytics BIOC Medium

Kubernetes vulnerability scanner activity

A Kubernetes cluster was scanned by a known vulnerability scanner.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002) Discovery (TA0007)
ATT&CK techniques: Deploy Container (T1610) Container and Resource Discovery (T1613)
Detector tags: Kubernetes - AGENT
Attacker's goals:

Usage of known tools and frameworks to exploit Kubernetes clusters.

Investigative actions:

Check if there is an active attack against the Kubernetes cluster.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Kubernetes vulnerability scanner activity from within a Kubernetes Pod Medium