Elastic high stable kql

Kubernetes Pod Exec Potential Reverse Shell

Flags exec into a pod when the URL-decoded command payload resembles reverse-shell or bind-shell one-liners invocation patterns. Legitimate debug sessions sometimes use similar building blocks, but together these patterns align with post-exploitation interactive access and command-and-control.

View Source

Detection Logic

FROM logs-kubernetes.audit_logs-* metadata _id, _index, _version
| WHERE kubernetes.audit.objectRef.subresource == "exec"
  
AND kubernetes.audit.requestURI LIKE "*command=*"
| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI)
| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container
| stdin
| stdout
| stderr)=%{GREEDYDATA}"
| EVAL command = REPLACE(raw_commands, "command=", "")
| EVAL command = REPLACE(command, "&", " ")
| EVAL Esql.executed_command = REPLACE(command, "\\+", " ")
| WHERE Esql.executed_command IS NOT NULL 
AND command RLIKE """.*(/dev/tcp/
| /dev/udp/
| zsh/net/tcp
| zsh/net/udp
| nc\s+-e
| ncat\s+-e
| netcat\s+-e
| nc\s.*\s-c\s
| mkfifo
| socat\s.*exec
| socat\s.*pty
| bash\s+-i\s+>&
| 0>&1
| >&\s*/dev/tcp
| import\s+socket.*connect
| import\s+pty.*spawn
| socket\.socket.*connect
| IO::Socket::INET
| fsockopen
| TCPSocket\.new
| /inet/tcp/).*""" 
AND 
  // local service health check patterns
  NOT command RLIKE """.*/dev/tcp/(localhost
| 127\.0\.0\.1)/(8080
| 8443
| 9090
| 3000
| 5000
| 8888
| 80
| 443).*"""
| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace

Field Validations

Loading…

Comments (0)

Loading comments...