An unusual process in ingress-nginx has accessed a service-account token file
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Cloud
Detector Tags
Kubernetes - AGENT, Containers
ATT&CK Tactic
Initial Access (TA0001), Credential Access (TA0006)
ATT&CK Technique
Exploit Public-Facing Application (T1190), Unsecured Credentials (T1552)
Severity
High
Description
An unusual process in ingress-nginx has read a service-account token.
Attacker's Goals
An attacker is attempting to gain unauthorized access by leveraging valid credentials.
Investigative actions
Check if the process is intended to preform these actions.
PreviousAn unusual cloud identity was granted permissions to a BigQuery resource
NextAn unusual read activity of cloud object
Was this helpful?
