Elastic low stable eql

Direct Interactive Kubernetes API Request by Unusual Utilities

This rule leverages a combination of Defend for Containers and Kubernetes audit logs to detect the execution of direct interactive Kubernetes API requests via unusual utilities. An adversary may need to execute direct interactive Kubernetes API requests to gain access to the Kubernetes API server or other resources within the cluster. These requests are often used to enumerate the Kubernetes API server or other resources within the cluster, and may indicate an attempt to move laterally within the cluster.

View Source

Detection Logic

sequence with maxspan=1s
  [process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and process.interactive == true and
  container.id like "*" and
  /* Covered by the rule "Direct Interactive Kubernetes API Request by Common Utilities" */
  not (
     process.name in ("wget", "curl", "openssl", "socat", "ncat", "kubectl") or
     (
       /* Account for tools that execute utilities as a subprocess, in this case the target utility name will appear as a process arg */
       process.name in ("bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "busybox") and
       process.args in (
         "wget", "/bin/wget", "/usr/bin/wget", "/usr/local/bin/wget",
         "ssl_client", "/bin/ssl_client", "/usr/bin/ssl_client", "/usr/local/bin/ssl_client",
         "curl", "/bin/curl", "/usr/bin/curl", "/usr/local/bin/curl",
         "openssl", "/bin/openssl", "/usr/bin/openssl", "/usr/local/bin/openssl",
         "socat", "/bin/socat", "/usr/bin/socat", "/usr/local/bin/socat",
         "ncat", "/bin/ncat", "/usr/bin/ncat", "/usr/local/bin/ncat",
         "kubectl", "/bin/kubectl", "/usr/bin/kubectl", "/usr/local/bin/kubectl"
       ) and
       /* default exclusion list to not FP on default multi-process commands */
       not process.args in (
         "which", "/bin/which", "/usr/bin/which", "/usr/local/bin/which",
         "man", "/bin/man", "/usr/bin/man", "/usr/local/bin/man",
         "chmod", "/bin/chmod", "/usr/bin/chmod", "/usr/local/bin/chmod",
         "chown", "/bin/chown", "/usr/bin/chown", "/usr/local/bin/chown"
       )
     ) or
     /* General exclusions for utilities that are not typically used for Kubernetes API requests */
     process.name in (
       "sleep", "head", "tail", "apk", "apt", "apt-get", "dnf", "microdnf", "yum", "zypper", "tdnf",
       "pacman", "rpm", "dpkg"
     )
   )] by orchestrator.resource.name
  [any where
     data_stream.dataset == "kubernetes.audit_logs" and
     kubernetes.audit.stage in ("ResponseStarted","ResponseComplete") and
     kubernetes.audit.verb in ("get", "list", "watch", "create", "patch", "update") and
     (
       kubernetes.audit.objectRef.resource in (
         "pods", "secrets", "serviceaccounts", "configmaps",
         "roles", "rolebindings", "clusterroles", "clusterrolebindings",
         "deployments", "daemonsets", "statefulsets", "jobs", "cronjobs",
         "nodes", "namespaces",
         "selfsubjectaccessreviews", "selfsubjectrulesreviews", "subjectaccessreviews"
       )
       or (
         kubernetes.audit.objectRef.resource == "pods" and
         kubernetes.audit.objectRef.subresource in ("exec", "attach", "portforward", "log")
       )
     )
  ] by `kubernetes.audit.user.extra.authentication.kubernetes.io/pod-name`

False Positives

  • There is a potential for false positives if the direct interactive Kubernetes API requests are used for legitimate purposes, such as debugging or troubleshooting. It is important to investigate any alerts generated by this rule to determine if they are indicative of malicious activity or part of legitimate container activity.
  • There is a risk of false positives if there are several containers named the same, as the rule may correlate the request to the wrong container.

Field Validations

Loading…

Comments (0)

Loading comments...