Elastic high stable kql

GKE Secret get or list with Suspicious User Agent

Detects successful GKE secret get or list operations where the user agent matches scripting runtimes, minimal HTTP clients, or offensive-distribution fingerprints rather than typical kubectl or controller traffic.

View Source

Detection Logic

data_stream.dataset:gcp.audit and service.name:"k8s.io" and event.outcome:success and
event.action:("io.k8s.core.v1.secrets.list" or "io.k8s.core.v1.secrets.get") and user_agent.original:(
  curl* or python* or Python* or wget* or Go-http* or perl* or java* or node* or php* or *distrib#kali* or *kali-amd64* or
  *kali-arm64* or Bun* or axios* or undici*
)

False Positives

  • Approved scripts, CI jobs, or penetration tests may use generic HTTP clients. Validate tickets and identity scope before treating as compromise.

Field Validations

Loading…

Comments (0)

Loading comments...