Analytics BIOC Medium

Kubernetes vulnerability scanning tool usage

A known vulnerability scanning tool was used within a Kubernetes cluster.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Execution (TA0002) Discovery (TA0007)
ATT&CK techniques: Deploy Container (T1610) Container and Resource Discovery (T1613)
Detector tags: Kubernetes - API
Attacker's goals:

Usage of known tools and frameworks to exploit Kubernetes clusters.

Investigative actions:

Check if this activity is expected (e.g. penetration testing). Determine which Kubernetes resources were affected. Review additional events for any suspicious activity within the cluster.

Test period:
N/A (single event)
Deduplication:
5 Days
2 variations:
  • Kubernetes vulnerability scanning tool usage within a pod Medium
  • External Kubernetes vulnerability scanning tool usage Medium