For the complete documentation index, see llms.txt. This page is also available as Markdown.

An unusual process in ingress-nginx has accessed a service-account token file

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Cloud

Detector Tags

Kubernetes - AGENT, Containers

ATT&CK Tactic

Initial Access (TA0001), Credential Access (TA0006)

ATT&CK Technique

Exploit Public-Facing Application (T1190), Unsecured Credentials (T1552)

Severity

High

Description

An unusual process in ingress-nginx has read a service-account token.

Attacker's Goals

An attacker is attempting to gain unauthorized access by leveraging valid credentials.

Investigative actions

  • Check if the process is intended to preform these actions.

Was this helpful?