Files
elastic-detection-rules/detection_rules/etc
Samirbous 054e02247f [New] Kubernetes API Server Proxying Request to Kubelet
Detects non-system identities using the Kubernetes nodes/proxy API to proxy requests through the API server directly to a node's Kubelet. The nodes/proxy subresource allows any principal with this RBAC permission to reach the Kubelet API on any worker node without needing direct network access or Kubelet TLS certificates. Through this proxy path,
an attacker can list all pod specifications including environment variable secrets, read Kubelet configuration and PKI material, retrieve container logs, and access running pod metadata across all workloads on the target node. Monitoring and health check endpoints such as /metrics, /healthz, and /stats are excluded to reduce noise from legitimate
observability tooling.
2026-05-05 16:58:18 +01:00
..
2026-04-23 00:13:05 +05:30
2026-04-23 00:13:05 +05:30