elastic
high
kql
GKE Pod Exec Sensitive File or Credential Path Access
Detects successful GKE pod exec sessions where the executed command references high-value host or in-cluster paths:
mounted service account or platform tokens, kubelet and control-plane configuration areas, host identity stores, root
or home credential directories, common private-key and keystore extensions, process environment dumps, and configuration
filenames suggestive of embedded secrets. Attackers with pods/exec often use these one-liners to steal credentials
before lateral movement or pri