detect-privilege-escalation-k8s
Installation
SKILL.md
detect-privilege-escalation-k8s
Attack patterns detected
This skill implements four independent detection rules, each producing a separate OCSF 1.8 Detection Finding (class 2004) with MITRE ATT&CK populated inside finding_info.attacks[].
Rule 1: Service-account secret enumeration + read (T1552.007)
A service account that lists secrets and then gets an individual secret within a short window is a strong signal of a compromised pod rooting around for credentials. Legitimate workloads that need secrets mount them as files — they don't call the K8s API for them.
- Trigger: same
system:serviceaccount:*actor performslistonsecretsand later performsgetonsecretsin the same namespace within the window (default: 5 minutes) - MITRE: T1552.007 — Unsecured Credentials: Container API
- Severity: High (4)
- Observables:
session.actor,session.namespace,secret.name(from thegetcall),time.window
Rule 2: Service-account pod exec (T1611)
A service account calling create on the pods/exec subresource is attempting to get a shell inside a running pod. No legitimate workload (as opposed to a human operator) does this.