detect-privilege-escalation-k8s

Installation
SKILL.md

detect-privilege-escalation-k8s

Attack patterns detected

This skill implements four independent detection rules, each producing a separate OCSF 1.8 Detection Finding (class 2004) with MITRE ATT&CK populated inside finding_info.attacks[].

Rule 1: Service-account secret enumeration + read (T1552.007)

A service account that lists secrets and then gets an individual secret within a short window is a strong signal of a compromised pod rooting around for credentials. Legitimate workloads that need secrets mount them as files — they don't call the K8s API for them.

  • Trigger: same system:serviceaccount:* actor performs list on secrets and later performs get on secrets in the same namespace within the window (default: 5 minutes)
  • MITRE: T1552.007 — Unsecured Credentials: Container API
  • Severity: High (4)
  • Observables: session.actor, session.namespace, secret.name (from the get call), time.window

Rule 2: Service-account pod exec (T1611)

A service account calling create on the pods/exec subresource is attempting to get a shell inside a running pod. No legitimate workload (as opposed to a human operator) does this.

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
detect-privilege-escalation-k8s — msaad00/cloud-ai-security-skills