Analytics
Low
✕
Potential kubelet impersonation attempt
A process accessed both the Kubelet credentials and the Kubernetes CA certificate, indicating an attempt to impersonate the node agent and communicate with the API server.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:
Impersonate the node agent to gain control over the cluster.
Investigative actions:
Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day
1 variation:
- Potential kubelet impersonation attempt by an unusual process Medium (parent: Low)