Analytics
Low
✕
Suspicious access to Kubernetes API with kubelet credentials
A combination of signals has been detected indicating that kubelet credentials were used inside a pod to access the Kubernetes API. This activity suggests an attempt to escalate privileges or move laterally within the cluster.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Exfiltration (TA0010) Collection (TA0009)
ATT&CK techniques: Data from Cloud Storage (T1530) Automated Exfiltration (T1020)
Detector tags: Cloud Data Asset Exfiltration Data Detection & Response
Attacker's goals:
Usage of the Kubernetes API server to perform operations inside the cluster.
Investigative actions:
Check if there is an active attack against the Kubernetes cluster.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day
1 variation:
- Suspicious access to Kubernetes API with kubelet credentials from unusual pod Medium (parent: Low)