New Kubernetes privileged pod created
Set up the kubernetes integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when a privileged pod is created. Privileged pods remove container isolation which allows privileged actions on the host.
Strategy
This rule monitors when a pod (@objectRef.resource:pods
) is created (@http.method:create
) and the privileged security context (@requestObject.spec.containers.securityContext.privileged
) is true
.
Triage & Response
Determine if the pod should be privileged.
Changelog
- 7 May 2024 - Updated detection query to include logs from Azure Kubernetes Service.
- 16 July 2024 - Updated detection query to include logs from Google Kubernetes Engine.