Analytics BIOC
Medium
✕
Suspicious Kubernetes pod token access
A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:
Gain access to the Kubernetes environment.
Investigative actions:
Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- Suspicious Kubernetes pod token access via remote access High (parent: Medium)
- Suspicious Kubernetes pod token access by an unusual pod High (parent: Medium)
- Suspicious Kubernetes pod token access by an unusual process Medium