A Kubernetes API operation was successfully invoked by an anonymous user
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs
Detection Modules
Cloud
Detector Tags
Kubernetes - API
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Valid Accounts: Default Accounts (T1078.001)
Severity
Medium
Description
An unauthenticated user successfully invoked API calls within the Kubernetes cluster.
Attacker's Goals
Gain initial access to a Kubernetes cluster.
Investigative actions
Determine which resources were accessed anonymously.
Verify whether the affected resource should be accessed by unauthenticated users.
Variations
PreviousA Google Workspace user was removed from a group
NextA Kubernetes cluster role binding was created or deleted
Was this helpful?
