A Kubernetes dashboard service account was used outside the cluster
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs
Detection Modules
Cloud
Detector Tags
Kubernetes - API
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
External Remote Services (T1133)
Severity
Medium
Description
A Kubernetes dashboard service account was successfully used externally of the Kubernetes environment, which may indicate that the dashboard is exposed to the internet and does not require authentication.
Attacker's Goals
Gain initial access to the Kubernetes cluster.
Investigative actions
Determine which Kubernetes resources were accessed through the dashboard.
Check whether any changes were made to the Kubernetes cluster.
Variations
Was this helpful?
