Kubernetes admission controller activity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs
Detection Modules
Cloud
Detector Tags
Kubernetes - API
ATT&CK Tactic
Persistence (TA0003), Credential Access (TA0006)
ATT&CK Technique
Valid Accounts (T1078), Unsecured Credentials: Container API (T1552.007)
Severity
Informational
Description
A Kubernetes admission controller has been created or modified.
Attacker's Goals
Intercept the requests to the Kubernetes API sever, records secrets, and other sensitive information.
Modify requests to the Kubernetes API sever.
Investigative actions
Verify whether the identity should use Kubernetes admission controllers.
Examine the role of the Kubernetes admission controller and its intended function.
Investigate other operations that were performed by the identity within the cluster.
Variations
Was this helpful?
