Analytics BIOC
Informational
✕
Unusual Kubernetes service account file read
An unusual process opened a Kubernetes service account file for the first time.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Kubernetes - AGENT Kubernetes Credentials Theft Analytics
Attacker's goals:
Utilize the Kubernetes service account files to perform additional actions on the cluster.
Investigative actions:
Check the exposed Kubernetes service account usage in the cluster. Check if any other suspicious activity was performed inside the pod.
- Test period:
- N/A (single event)
- Deduplication:
- 7 Days
7 variations:
- Unusual Kubernetes service account file read within a new pod Informational
- Kubernetes service account file read Informational
- Suspicious Kubernetes service account file read from the projected volume path Medium (parent: Informational)
- Suspicious Kubernetes service account token read via an interactive shell Medium (parent: Informational)
- Suspicious Kubernetes service account token read by an unusual process Low (parent: Informational)
- Suspicious Kubernetes service account file read by an unusual process Low (parent: Informational)
- Suspicious Kubernetes service account token read Low (parent: Informational)