fixedaddedcondition

This commit is contained in:
Rod Soto
2020-06-25 14:36:18 -04:00
parent 3c9fd3d376
commit 6ea3604481
@@ -6,7 +6,7 @@ id: 1bba382b-07fd-4ffa-b390-8002739b76e8
known_false_positives: "Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection."
name: "Azure AKS Kubernetes cluster sensitive object access detection"
references: []
search: "sourcetype=mscs:storage:blob:json index=azure_test category=kube-audit | spath input=properties.log| search objectRef.resource=secrets OR configmaps |table user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason |dedup user.username user.groups{} |`kubernetes_azure_detect_sensitive_object_access`"
search: "sourcetype=mscs:storage:blob:json category=kube-audit | spath input=properties.log| search objectRef.resource=secrets OR configmaps user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow |table user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason |dedup user.username user.groups{} |`kubernetes_azure_detect_sensitive_object_access`"
tags:
analytics_story:
- "Kubernetes Sensitive Object Access Activity"