Access to Kubernetes configuration file
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Kubernetes - AGENT
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Unsecured Credentials: Credentials In Files (T1552.001)
Severity
Informational
Description
A process accessed a Kubernetes node configuration file.
Attacker's Goals
Gain access to the Kubernetes environment.
Investigative actions
Look for additional suspicious activities.
Verify if the exposed credentials were used to access the API server.
Investigate which operations were used against the Kubernetes cluster with the exposed credentials.
Variations
PreviousAccess to Kubernetes CA certificate file
NextAccess to sensitive host files from within a Kubernetes pod
Was this helpful?
