Analytics Story: Kubernetes Sensitive Role Activity

REMOVED ANALYTIC STORY

This analytic story has been removed from the Splunk Threat Research content library and is no longer maintained or supported.

Reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity

Removed in version: 5.2.0

Replacement: Kubernetes Security

If you have any questions or concerns, please reach out to us at research@splunk.com.

Description

This story addresses detection and response around Sensitive Role usage within a Kubernetes clusters against cluster resources and namespaces.

Why it matters

Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitive roles within its architecture, specifically configmaps and secrets, if accessed by an attacker can lead to further compromise. These searches allow operator to detect suspicious requests against Kubernetes role activities

Detections

Name ▲▼ Technique ▲▼ Type ▲▼

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼

References


Version: 1