For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual Kubernetes service account file read

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

7 Days

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

Kubernetes - AGENT, Kubernetes Credentials Theft Analytics

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Informational

Description

An unusual process opened a Kubernetes service account file for the first time.

Attacker's Goals

Utilize the Kubernetes service account files to perform additional actions on the cluster.

Investigative actions

  • Check the exposed Kubernetes service account usage in the cluster.

  • Check if any other suspicious activity was performed inside the pod.

Variations

Unusual Kubernetes service account file read within a new pod

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Informational

Description

An unusual process opened a Kubernetes service account file for the first time.

Attacker's Goals

Utilize the Kubernetes service account files to perform additional actions on the cluster.

Investigative actions

  • Check the exposed Kubernetes service account usage in the cluster.

  • Check if any other suspicious activity was performed inside the pod.

Kubernetes service account file read

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Informational

Description

An unusual process opened a Kubernetes service account file for the first time.

Attacker's Goals

Utilize the Kubernetes service account files to perform additional actions on the cluster.

Investigative actions

  • Check the exposed Kubernetes service account usage in the cluster.

  • Check if any other suspicious activity was performed inside the pod.

Suspicious Kubernetes service account file read from the projected volume path

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Medium

Description

An unusual process opened a Kubernetes service account file for the first time.

Attacker's Goals

Utilize the Kubernetes service account files to perform additional actions on the cluster.

Investigative actions

  • Check the exposed Kubernetes service account usage in the cluster.

  • Check if any other suspicious activity was performed inside the pod.

Suspicious Kubernetes service account token read via an interactive shell

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Medium

Description

An unusual process opened a Kubernetes service account file for the first time.

Attacker's Goals

Utilize the Kubernetes service account files to perform additional actions on the cluster.

Investigative actions

  • Check the exposed Kubernetes service account usage in the cluster.

  • Check if any other suspicious activity was performed inside the pod.

Suspicious Kubernetes service account token read by an unusual process

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Low

Description

An unusual process opened the Kubernetes service account token file for the first time.

Attacker's Goals

Utilize the Kubernetes service account files to perform additional actions on the cluster.

Investigative actions

  • Check the exposed Kubernetes service account usage in the cluster.

  • Check if any other suspicious activity was performed inside the pod.

Suspicious Kubernetes service account file read by an unusual process

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Low

Description

An unusual process opened a Kubernetes service account file for the first time.

Attacker's Goals

Utilize the Kubernetes service account files to perform additional actions on the cluster.

Investigative actions

  • Check the exposed Kubernetes service account usage in the cluster.

  • Check if any other suspicious activity was performed inside the pod.

Suspicious Kubernetes service account token read

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Low

Description

An unusual process opened the Kubernetes service account token file for the first time.

Attacker's Goals

Utilize the Kubernetes service account files to perform additional actions on the cluster.

Investigative actions

  • Check the exposed Kubernetes service account usage in the cluster.

  • Check if any other suspicious activity was performed inside the pod.

Was this helpful?