Elastic medium stable kql
GKE Pod Created With HostPID
Detects GKE pod create, update, or patch events that enable host PID namespace sharing. HostPID exposes host processes and can support privilege escalation, especially with ptrace or privileged containers. System identities and controller-owned workloads are excluded.
Detection Logic
data_stream.dataset:gcp.audit and
event.action:("io.k8s.core.v1.pods.create" or "io.k8s.core.v1.pods.update" or "io.k8s.core.v1.pods.patch") and
gcp.audit.request.spec.hostPID:true and not user.email:system\:* and
not gcp.audit.request.metadata.ownerReferences.kind:("ReplicaSet" or "DaemonSet" or "StatefulSet") False Positives
- ⚠ Debug pods may legitimately use hostPID. Exclude trusted admin workflows after baselining.
Field Validations
Loading…
Comments (0)
Loading comments...