Access to sensitive host files from within a Kubernetes pod
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Kubernetes - AGENT, Kubernetes Credentials Theft Analytics
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Escape to Host (T1611)
Severity
Informational
Description
A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt.
Attacker's Goals
Access to the host filesystem.
Investigative actions
Look for additional suspicious activities.
Verify if the exposed files were used for malicious activity.
Investigate which operations were used against the Kubernetes cluster with the exposed credentials.
Variations
Was this helpful?
