detect-sensitive-secret-read-k8s

Installation
SKILL.md

detect-sensitive-secret-read-k8s

Use when

  • Kubernetes secret-access telemetry is already normalized by ingest-k8s-audit-ocsf
  • you want a direct-read detector for high-value secret names
  • you want native or OCSF findings for targeted secret access attempts

Attack pattern

Workloads should mount the secrets they need as files — the K8s API isn't supposed to be the credential read path at runtime. When an audit log shows a workload's service account calling get or list on a secret whose name matches a known sensitive pattern, that's a direct credential-read attempt. It's the MITRE T1552.007 technique as observed by kube-apiserver rather than by a pod-level hook.

This skill complements detect-privilege-escalation-k8s Rule 1 (which requires a list + get correlation in a window). Rule 1 catches enumeration-then-read. This skill catches targeted reads with no preceding list — an attacker who already knows the secret name.

Detection logic

For each OCSF API Activity event on the secrets resource type:

Installs
3
GitHub Stars
3
First Seen
Apr 20, 2026
detect-sensitive-secret-read-k8s — msaad00/cloud-ai-security-skills