Kubernetes Pod Created With Sensitive Volume
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs
Detection Modules
Cloud
Detector Tags
Kubernetes - API
ATT&CK Tactic
Privilege Escalation (TA0004), Execution (TA0002)
ATT&CK Technique
Escape to Host (T1611), Deploy Container (T1610)
Severity
Informational
Description
An identity created a Kubernetes Pod with a sensitive volume, allowing the Pod to have read or write permissions on the host's filesystem This could suggest an effort by an adversary to access sensitive files on the host and employ techniques for escalating privileges.
Attacker's Goals
Gain access to the host's filesystem.
Gain root access to the host.
Investigative actions
Check the identity's role designation in the organization.
Inspect for any additional suspicious activities inside the Kubernetes Pod.
Variations
Was this helpful?
