Azure Activity Logs: RoleBinding/ClusterRoleBinding Created/Patched or Deleted (Kubernetes RBAC)

Alerts on Azure Kubernetes RBAC RoleBinding/ClusterRoleBinding write or delete events that may indicate permission changes.

FreeUnreviewedSigmamediumv1
title: "Azure Activity Logs: RoleBinding/ClusterRoleBinding Created/Patched or Deleted (Kubernetes RBAC)"
id: 3a4bd822-c7ed-48f9-9ccd-97f4b034b088
status: test
description: This rule matches Azure Kubernetes RBAC authorization Activity Log events indicating write or delete operations on RoleBindings and ClusterRoleBindings in connected clusters. Such changes are critical because they can grant, alter, or remove permissions that control access to Kubernetes resources and cluster capabilities. It relies on Azure Activity Logs telemetry capturing operation names for write and delete actions on these RBAC objects.
references:
  - https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
  - https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
  - https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
  - https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_kubernetes_rolebinding_modified_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
  - attack.impact
  - attack.credential-access
  - attack.t1485
  - attack.t1496
  - attack.t1489
logsource:
  product: azure
  service: activitylogs
detection:
  selection:
    operationName:
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/RBAC.AUTHORIZATION.K8S.IO/CLUSTERROLEBINDINGS/WRITE
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/RBAC.AUTHORIZATION.K8S.IO/CLUSTERROLEBINDINGS/DELETE
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/RBAC.AUTHORIZATION.K8S.IO/ROLEBINDINGS/WRITE
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/RBAC.AUTHORIZATION.K8S.IO/ROLEBINDINGS/DELETE
  condition: selection
falsepositives:
  - RoleBinding/ClusterRoleBinding being modified and deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  - RoleBinding/ClusterRoleBinding modification from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
  - id: 25cb259b-bbdc-4b87-98b7-90d7c72f8743
    type: derived

What it detects

This rule matches Azure Kubernetes RBAC authorization Activity Log events indicating write or delete operations on RoleBindings and ClusterRoleBindings in connected clusters. Such changes are critical because they can grant, alter, or remove permissions that control access to Kubernetes resources and cluster capabilities. It relies on Azure Activity Logs telemetry capturing operation names for write and delete actions on these RBAC objects.

Known false positives

  • RoleBinding/ClusterRoleBinding being modified and deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  • RoleBinding/ClusterRoleBinding modification from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.