mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
2.3 KiB
2.3 KiB
title, last_modified_at, toc, toc_label, tags
| title | last_modified_at | toc | toc_label | tags | ||||
|---|---|---|---|---|---|---|---|---|
| Kubernetes Scanning Activity | 2020-04-15 | true |
|
Try in Splunk Security Cloud{: .btn .btn--success}
Description
This story addresses detection against Kubernetes cluster fingerprint scan and attack by providing information on items such as source ip, user agent, cluster names.
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel:
- Last Updated: 2020-04-15
- Author: Rod Soto, Splunk
- ID: a9ef59cf-e981-4e66-9eef-bb049f695c09
Narrative
Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitve information and management priviledges of production workloads, microservices and applications. These searches allow operator to detect suspicious unauthenticated requests from the internet to kubernetes cluster.
Detections
Reference
source | version: 1