Azure Activity Logs: Kubernetes Network Policy Write/Delete Operations
Alerts on Azure Activity Log events that modify or remove Kubernetes network policies for connected clusters.
FreeUnreviewedSigmamediumv1
azure-activity-logs-kubernetes-network-policy-write-delete-operations-08d6ac24
title: "Azure Activity Logs: Kubernetes Network Policy Write/Delete Operations"
id: 6c95d129-666f-43b6-b90e-90e3e5f0719f
status: test
description: This rule flags Azure Activity Log events where Kubernetes network policies are written or deleted on connected clusters. Attackers can abuse network policy changes to alter pod-to-pod or pod-to-network traffic controls and disrupt or evade security controls. It relies on Azure Activity Logs operationName values for NETWORKPOLICIES write and delete across the K8S.IO and EXTENSIONS paths.
references:
- https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
- https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
- https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
- https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_kubernetes_network_policy_change.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
- attack.impact
- attack.credential-access
- attack.t1485
- attack.t1496
- attack.t1489
logsource:
product: azure
service: activitylogs
detection:
selection:
operationName:
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/NETWORKING.K8S.IO/NETWORKPOLICIES/WRITE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/NETWORKING.K8S.IO/NETWORKPOLICIES/DELETE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/EXTENSIONS/NETWORKPOLICIES/WRITE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/EXTENSIONS/NETWORKPOLICIES/DELETE
condition: selection
falsepositives:
- Network Policy being modified and deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Network Policy being modified and deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
- id: 08d6ac24-c927-4469-b3b7-2e422d6e3c43
type: derived
What it detects
This rule flags Azure Activity Log events where Kubernetes network policies are written or deleted on connected clusters. Attackers can abuse network policy changes to alter pod-to-pod or pod-to-network traffic controls and disrupt or evade security controls. It relies on Azure Activity Logs operationName values for NETWORKPOLICIES write and delete across the K8S.IO and EXTENSIONS paths.
Known false positives
- Network Policy being modified and deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Network Policy being modified and deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.