Analytics Low

Suspicious access to Kubernetes API with kubelet credentials

A combination of signals has been detected indicating that kubelet credentials were used inside a pod to access the Kubernetes API. This activity suggests an attempt to escalate privileges or move laterally within the cluster.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Exfiltration (TA0010) Collection (TA0009)
ATT&CK techniques: Data from Cloud Storage (T1530) Automated Exfiltration (T1020)
Detector tags: Cloud Data Asset Exfiltration Data Detection & Response
Attacker's goals:

Usage of the Kubernetes API server to perform operations inside the cluster.

Investigative actions:

Check if there is an active attack against the Kubernetes cluster.

Test period:
10 Minutes
Deduplication:
1 Day
1 variation:
  • Suspicious access to Kubernetes API with kubelet credentials from unusual pod Medium (parent: Low)