A Kubernetes cluster role binding was created or deleted
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs
Detection Modules
Cloud
Detector Tags
Kubernetes - API
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Account Manipulation: Additional Container Cluster Roles (T1098.006)
Severity
Informational
Description
A Kubernetes cluster role binding was created or deleted.
Attacker's Goals
Escalate privileges to gain access to restricted resources in the Kubernetes cluster.
Investigative actions
Check which changes were made to the Kubernetes cluster role binding.
PreviousA Kubernetes API operation was successfully invoked by an anonymous user
NextA Kubernetes cluster role was created
Was this helpful?
