elastic
medium
kql
Azure AKS Attempted User Exec into Pod
Detects an AKS (Azure Kubernetes Service) identity establishing an exec session into a pod. Interactive command
execution inside a workload via kubectl exec is a common post-compromise technique used to access secrets, run tooling,
and expand access from a foothold container. Node, control-plane, and kube-system service account identities are
excluded, so workload service accounts and users, the identities an adversary is most likely to abuse, remain in scope.