elastic
medium
kql
GKE Sensitive RBAC Change Followed by Workload Modification
Detects when the same GKE identity creates or modifies a Role or ClusterRole with high-risk permissions
(wildcard access, RBAC escalation verbs, or access to secrets / privileged APIs) and also creates or patches
a DaemonSet, Deployment, or CronJob within five minutes. This correlation is consistent with RBAC-based
privilege escalation followed by payload deployment.