Elastic medium stable kql
GKE Anonymous Request Authorized by Unusual User Agent
Detects successful GKE API requests from unauthenticated anonymous identities using an unusual user agent. Attackers may rely on anonymous access for initial cluster access or to avoid attribution. Matches "system:anonymous" / "system:unauthenticated" and GKE audit rows where the principal is missing (common for unauthenticated clients). Common kube-probe health checks (readyz/livez/healthz/version) are excluded.
Detection Logic
data_stream.dataset:gcp.audit and service.name:k8s.io and event.outcome:success and client.user.email:("system:anonymous" or "system:unauthenticated" or not *) and user_agent.original:(* and not (*kubernetes/$Format or kube-probe*)) and not gcp.audit.resource_name:(healthz or livez or readyz or version or .well-known*) False Positives
- ⚠ Anonymous API access is a dangerous default. Health probes are excluded; investigate all other authorized anonymous requests and disable anonymous authentication where possible.
Field Validations
Loading…
Comments (0)
Loading comments...