Analytics BIOC Medium

Suspicious Kubernetes pod token access

A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:

Gain access to the Kubernetes environment.

Investigative actions:

Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Suspicious Kubernetes pod token access via remote access High (parent: Medium)
  • Suspicious Kubernetes pod token access by an unusual pod High (parent: Medium)
  • Suspicious Kubernetes pod token access by an unusual process Medium