Kubernetes enumeration activity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
7 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs
Detection Modules
Cloud
Detector Tags
Kubernetes - API
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Container and Resource Discovery (T1613), Cloud Service Discovery (T1526)
Severity
Informational
Description
An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment.
Attacker's Goals
Map the cluster environment and detect potential resources to abuse.
Investigative actions
Check the identity's role designation in the organization.
Identify which available resources were discovered.
Investigate if the discovered resources were used to extract sensitive information or perform other attacks in the cloud environment.
Variations
Was this helpful?
