Sensitive namespace modified using kubectl
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect the use of kubectl
inside a container to modify the ConfigMap of a sensitive namespace.
Strategy
This detection triggers when kubectl
is executed with specific arguments related to modifying the ConfigMap of a sensitive namespace.
Triage and response
- Identify the purpose of the configuration being applied, and determine if it is authorized.
- If it is not authorized, identify and revoke the credential used to authenticate to the Kubernetes API.
- Initiate the incident response process.
- Remediate compromised resources and repair the root cause.
Requires Agent version 7.27 or greater