Files
splunk-security_content/stories/kubernetes_scanning_activity.yml
2021-07-21 12:26:15 +02:00

24 lines
922 B
YAML

name: Kubernetes Scanning Activity
id: a9ef59cf-e981-4e66-9eef-bb049f695c09
version: 1
date: '2020-04-15'
author: Rod Soto, Splunk
description: This story addresses detection against Kubernetes cluster fingerprint
scan and attack by providing information on items such as source ip, user agent,
cluster names.
narrative: Kubernetes is the most used container orchestration platform, this orchestration
platform contains sensitve information and management priviledges of production
workloads, microservices and applications. These searches allow operator to detect
suspicious unauthenticated requests from the internet to kubernetes cluster.
references:
- https://github.com/splunk/cloud-datamodel-security-research
tags:
analytic_story: Kubernetes Scanning Activity
category:
- Cloud Security
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Security Monitoring