elastic
high
eql
Potential Direct Kubelet Access via Process Arguments
Detects potential direct Kubelet API access attempts on Linux by identifying process executions whose arguments contain
URLs targeting Kubelet ports (10250/10255). Adversaries may probe or access Kubelet endpoints to enumerate pods, fetch
logs, or attempt remote execution, which can enable discovery and lateral movement in Kubernetes environments.