Azure Kubernetes Connected Cluster Created or Deleted via Activity Logs
Alerts on Azure Activity Log operations that write or delete Kubernetes Connected Clusters.
FreeUnreviewedSigmalowv1
azure-kubernetes-connected-cluster-created-or-deleted-via-activity-logs-9541f321
title: Azure Kubernetes Connected Cluster Created or Deleted via Activity Logs
id: 387fa0a1-81f6-499e-b9aa-4f63ec117ca2
status: test
description: This rule flags Azure Activity Log events where a Kubernetes Connected Cluster is created or deleted. Such changes can indicate provisioning activity or an attempt to disrupt containerized workloads. It relies on Activity Log telemetry matching MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/WRITE and MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/DELETE operation names.
references:
- https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
- https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
- https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
- https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_kubernetes_cluster_created_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
- attack.impact
- attack.t1485
- attack.t1496
- attack.t1489
logsource:
product: azure
service: activitylogs
detection:
selection:
operationName:
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/WRITE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/DELETE
condition: selection
falsepositives:
- Kubernetes cluster being created or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Kubernetes cluster created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
- id: 9541f321-7cba-4b43-80fc-fbd1fb922808
type: derived
What it detects
This rule flags Azure Activity Log events where a Kubernetes Connected Cluster is created or deleted. Such changes can indicate provisioning activity or an attempt to disrupt containerized workloads. It relies on Activity Log telemetry matching MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/WRITE and MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/DELETE operation names.
Known false positives
- Kubernetes cluster being created or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Kubernetes cluster created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.