For the complete documentation index, see llms.txt. This page is also available as Markdown.

Execution of command from within a Kubernetes pod using kubelet credentials

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

Kubernetes - AGENT

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Access Token Manipulation (T1134)

Severity

Low

Description

A command was executed from within a Kubernetes pod using Kubelet credentials. This activity allows an attacker to impersonate the node and perform privileged operations against the cluster API.

Attacker's Goals

Usage of the Kubernetes API server to perform operations inside the cluster.

Investigative actions

Check if there is an active attack against the Kubernetes cluster.

Variations

Unusual execution of command from within a Kubernetes pod using kubelet credentials

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Access Token Manipulation (T1134)

Severity

Medium

Description

A command was executed from within a Kubernetes pod using Kubelet credentials. This activity allows an attacker to impersonate the node and perform privileged operations against the cluster API.

Attacker's Goals

Usage of the Kubernetes API server to perform operations inside the cluster.

Investigative actions

Check if there is an active attack against the Kubernetes cluster.

Was this helpful?