Execution of command from within a Kubernetes pod using kubelet credentials
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Access Token Manipulation (T1134)
Severity
Low
Description
A command was executed from within a Kubernetes pod using Kubelet credentials. This activity allows an attacker to impersonate the node and perform privileged operations against the cluster API.
Attacker's Goals
Usage of the Kubernetes API server to perform operations inside the cluster.
Investigative actions
Check if there is an active attack against the Kubernetes cluster.
Variations
PreviousExecution of an uncommon process with a local/domain user SID at early startup by a system binary
NextExecution of dllhost.exe with an empty command line
Was this helpful?
