Analytics Story: Kubernetes Sensitive Role Activity
REMOVED ANALYTIC STORY
This analytic story has been removed from the Splunk Threat Research content library and is no longer maintained or supported.
Reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
Removed in version: 5.2.0
Replacement: Kubernetes Security
If you have any questions or concerns, please reach out to us at research@splunk.com.
Description
This story addresses detection and response around Sensitive Role usage within a Kubernetes clusters against cluster resources and namespaces.
Why it matters
Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitive roles within its architecture, specifically configmaps and secrets, if accessed by an attacker can lead to further compromise. These searches allow operator to detect suspicious requests against Kubernetes role activities
Detections
| Name | Technique | Type |
|---|
Data Sources
| Name | Platform | Sourcetype | Source |
|---|
References
Version: 1