An Azure Kubernetes Role or Cluster-Role was modified
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
An Azure Kubernetes Role or Cluster-Role was modified or deleted. This could indicate malicious activity and should be investigated.
Attacker's Goals
Escalate privileges to gain access to restricted resources in Azure Kubernetes cluster.
Investigative actions
Review the role or ClusterRole changes made by the identity.
Determine whether the identity is authorized to perform these actions.
PreviousAn Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted
NextAn Azure Kubernetes Service Account was modified or deleted
Was this helpful?
