For the complete documentation index, see llms.txt. This page is also available as Markdown.

An Azure Kubernetes Role or Cluster-Role was modified

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Azure Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

An Azure Kubernetes Role or Cluster-Role was modified or deleted. This could indicate malicious activity and should be investigated.

Attacker's Goals

  • Escalate privileges to gain access to restricted resources in Azure Kubernetes cluster.

Investigative actions

  • Review the role or ClusterRole changes made by the identity.

  • Determine whether the identity is authorized to perform these actions.

Was this helpful?