A Kubernetes service account has enumerated its permissions
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs
Detection Modules
Cloud
Detector Tags
Kubernetes - API
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Container and Resource Discovery (T1613)
Severity
Informational
Description
A Kubernetes service account has enumerated its permissions using the self subject review API.
Attacker's Goals
Discover permissions to the Kubernetes cluster.
Investigative actions
Determine the scope of the Kubernetes service account permissions.
Review additional activity of the Kubernetes service account.
Variations
PreviousA Kubernetes service account executed an unusual API call
NextA Kubernetes service account was created or deleted
Was this helpful?
