Files
elastic-detection-rules/rules/integrations
Samirbous 674d0f63e9 [New] Kubernetes Secret get or list from Node or Pod Service Account (#5973)
* [New] Kubernetes Secret get or list from Node or Pod Service Account

Kubernetes audit identities for kubelet (`system:node:*`) and workloads (`system:serviceaccount:*`) are meant to operate with tight, predictable API usage. Direct `get` or `list` on the Secrets API from those principals is
often a sign of credential access.

* Update credential_access_kubernetes_secret_read_by_node_or_pod_service_account.toml

* Update credential_access_kubernetes_secret_read_by_node_or_pod_service_account.toml

(cherry picked from commit 338548a306)
2026-05-02 10:51:36 +00:00
..
2026-05-01 21:00:39 +00:00
2026-04-22 18:46:33 +00:00
2025-07-07 11:27:48 -04:00