Elastic medium stable kql
GKE API Request Failure Burst by User
Detects bursts of failed GKE API requests from a single user identity within a five-minute window. Repeated authorization failures across multiple actions can indicate credential stuffing, RBAC probing, or reconnaissance with stolen tokens.
Detection Logic
from logs-gcp.audit-* metadata _id, _index, _version
| eval Esql.time_interval = date_trunc(5 minutes, @timestamp)
| where data_stream.dataset == "gcp.audit"
and service.name == "k8s.io"
and event.outcome == "failure"
and event.type != "allowed"
and user.email is not null
and not to_string(user.email) rlike "(system:serviceaccount:
| system:gke-spiffe-controller
| system:kube-scheduler
| system:node:).*"
| stats
Esql.unique_actions = count_distinct(event.action),
Esql.failures_count = count(*),
Esql.actions = values(event.action),
Esql.resources = values(orchestrator.resource.name)
by user.email, source.ip, user_agent.original, data_stream.namespace, Esql.time_interval
| where Esql.failures_count >= 10
| keep Esql.*, user.email, source.ip, user_agent.original, data_stream.namespace Field Validations
Loading…
Comments (0)
Loading comments...