For the complete documentation index, see llms.txt. This page is also available as Markdown.

Kubernetes enumeration activity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

7 Days

Required Data

Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs

Detection Modules

Cloud

Detector Tags

Kubernetes - API

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Container and Resource Discovery (T1613), Cloud Service Discovery (T1526)

Severity

Informational

Description

An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment.

Attacker's Goals

Map the cluster environment and detect potential resources to abuse.

Investigative actions

  • Check the identity's role designation in the organization.

  • Identify which available resources were discovered.

  • Investigate if the discovered resources were used to extract sensitive information or perform other attacks in the cloud environment.

Variations

Suspicious Kubernetes enumeration activity

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Container and Resource Discovery (T1613), Cloud Service Discovery (T1526)

Severity

Informational

Description

An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment.

Attacker's Goals

Map the cluster environment and detect potential resources to abuse.

Investigative actions

  • Check the identity's role designation in the organization.

  • Identify which available resources were discovered.

  • Investigate if the discovered resources were used to extract sensitive information or perform other attacks in the cloud environment.

Was this helpful?