detect-sensitive-secret-read-k8s
Installation
SKILL.md
detect-sensitive-secret-read-k8s
Use when
- Kubernetes secret-access telemetry is already normalized by
ingest-k8s-audit-ocsf - you want a direct-read detector for high-value secret names
- you want native or OCSF findings for targeted secret access attempts
Attack pattern
Workloads should mount the secrets they need as files — the K8s API isn't supposed to be the credential read path at runtime. When an audit log shows a workload's service account calling get or list on a secret whose name matches a known sensitive pattern, that's a direct credential-read attempt. It's the MITRE T1552.007 technique as observed by kube-apiserver rather than by a pod-level hook.
This skill complements detect-privilege-escalation-k8s Rule 1 (which requires a list + get correlation in a window). Rule 1 catches enumeration-then-read. This skill catches targeted reads with no preceding list — an attacker who already knows the secret name.
Detection logic
For each OCSF API Activity event on the secrets resource type: