elastic
low
kql
GKE Secret Access via Unusual User Agent
Detects GKE secrets get or list requests from a previously unseen combination of source IP, identity, and user agent,
excluding the default Kubernetes client placeholder. Attackers who compromise a pod or steal a kubeconfig often use
curl, custom scripts, or atypical clients from a new host to read service-account tokens, registry credentials, or
application secrets. Anonymous identities are excluded; use dedicated anonymous-access rules for unauthenticated
probing.