Azure Activity Logs: Kubernetes AdmissionRegistration webhook configuration writes

Flags Azure activity log events writing Kubernetes admission webhook configurations (mutating or validating), indicating potential cluster request interception.

FreeReviewedSigma · Medium · v5
Product
azure
Service
activitylogs
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-11-25
Updated
2026-07-31

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags write operations to Azure Kubernetes AdmissionRegistration resources, indicating creation or modification of MutatingAdmissionWebhook and ValidatingAdmissionWebhook configuration in connected or managed clusters. Admission webhooks can intercept Kubernetes API requests and potentially alter or validate them, which makes them a persistence and stealth technique if an attacker can deploy malicious webhook behavior. The detection relies on Azure Activity Logs events with operationName patterns for AdmissionRegistration.K8S.IO and webhook configuration writes.

Related detections9 linkedT1078 — drag to rearrange
Kubernetes API Audit: Admission Webhook Configuration Modified
GCP Kubernetes audit events: Admission webhook configuration creates/updates
Malicious SD-WAN Compromise Credential Theft via loot_run.sh
Possible Next.js Middleware Auth Bypass via X-Middleware-Subrequest Header (CVE-2025-29927)
Possible SSRF via VMware Workspace One Access instanceHealth CVE-2021-22056
Suspicious Brutforce with Denied Access Due to Account Restrictions Policies (via security)
Suspicious Success Login Attempt on a Windows OpenSSH Server (via security)
Suspicious SQL Server - Connection Attempt Using a Disabled Account (via application)
Suspicious Lateral Movement Detection - Based on "special Groups" Feature (via security)
Azure Activity Logs: Kubernetes AdmissionRegistration webhook configuration writes
Pivot detection · T1078 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.