elastic
high
kql
Kubernetes Pod Exec Cloud Instance Metadata Access
Detects Kubernetes pod exec sessions whose decoded command line references cloud instance metadata endpoints or
equivalent hostnames and paths. Workloads that reach the link-local metadata IP, AWS IMDS paths, GCP computeMetadata,
Azure IMDS token routes, or encoded variants are often attempting to harvest role credentials, tokens, or instance
attributes from the underlying node or hypervisor boundary. That behavior is high risk in multi-tenant and regulated
environments because it can expose sho