Azure Activity Logs: Kubernetes Service Account Write, Delete, or Impersonate
Alerts on Azure Activity Log events where a Kubernetes service account is written, deleted, or impersonated.
FreeUnreviewedSigmamediumv1
azure-activity-logs-kubernetes-service-account-write-delete-or-impersonate-12d027c3
title: "Azure Activity Logs: Kubernetes Service Account Write, Delete, or Impersonate"
id: 62cbd0ee-8be9-4e3b-963c-6f85ec8eb639
status: test
description: This rule identifies Azure Activity Log events where a Kubernetes service account is modified via a write operation, removed via delete, or modified through an impersonation action. Attackers may abuse service account lifecycle changes to gain or shift permissions within an Azure Kubernetes environment. It relies on Azure Activity Log telemetry capturing the specific Microsoft.Kubernetes ConnectedClusters service account operation names and the corresponding event context.
references:
- https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
- https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
- https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
- https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_kubernetes_service_account_modified_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
- attack.impact
- attack.t1531
- attack.t1485
- attack.t1496
- attack.t1489
logsource:
product: azure
service: activitylogs
detection:
selection:
operationName:
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SERVICEACCOUNTS/WRITE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SERVICEACCOUNTS/DELETE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SERVICEACCOUNTS/IMPERSONATE/ACTION
condition: selection
falsepositives:
- Service account being modified or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Service account modified or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
- id: 12d027c3-b48c-4d9d-8bb6-a732200034b2
type: derived
What it detects
This rule identifies Azure Activity Log events where a Kubernetes service account is modified via a write operation, removed via delete, or modified through an impersonation action. Attackers may abuse service account lifecycle changes to gain or shift permissions within an Azure Kubernetes environment. It relies on Azure Activity Log telemetry capturing the specific Microsoft.Kubernetes ConnectedClusters service account operation names and the corresponding event context.
Known false positives
- Service account being modified or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Service account modified or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.