Elastic medium stable kql

Azure AKS Service Account Token Created via TokenRequest API

Detects an identity minting a service account token via the AKS (Azure Kubernetes Service) TokenRequest API (serviceaccounts/token), excluding known AKS control-plane and platform identities. Adversaries request service account tokens from a compromised identity to impersonate a workload, move laterally, or escalate privileges within the cluster. Coverage includes workload service accounts (system:serviceaccount:*), so a compromised in-cluster token minting a token for another service account is not excluded.

View Source

Detection Logic

data_stream.dataset:azure.platformlogs and
    event.action:"Microsoft.ContainerService/managedClusters/diagnosticLogs/Read" and
    azure.platformlogs.category:("kube-audit" or "kube-audit-admin") and
    azure.platformlogs.properties.log.stage:"ResponseComplete" and
    azure.platformlogs.properties.log.objectRef.resource:"serviceaccounts" and
    azure.platformlogs.properties.log.objectRef.subresource:"token" and
    azure.platformlogs.properties.log.verb:"create" and
    azure.platformlogs.properties.log.responseStatus.code:("200" or "201") and
    not azure.platformlogs.properties.log.user.username:(
        system\:node\:* or "aksService" or "hcpService" or "readinessChecker" or
        system\:serviceaccount\:kube-system\:*
    )

False Positives

  • Controllers, CI/CD systems, and platform components legitimately request service account tokens. Baseline the requesting identities and exclude verified automation after review.

Field Validations

Loading…

Comments (0)

Loading comments...