Azure Kubernetes Connected Cluster Created or Deleted via Activity Logs

Alerts on Azure Activity Log operations that write or delete Kubernetes Connected Clusters.

FreeUnreviewedSigmalowv1
title: Azure Kubernetes Connected Cluster Created or Deleted via Activity Logs
id: 387fa0a1-81f6-499e-b9aa-4f63ec117ca2
status: test
description: This rule flags Azure Activity Log events where a Kubernetes Connected Cluster is created or deleted. Such changes can indicate provisioning activity or an attempt to disrupt containerized workloads. It relies on Activity Log telemetry matching MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/WRITE and MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/DELETE operation names.
references:
  - https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
  - https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
  - https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
  - https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_kubernetes_cluster_created_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
  - attack.impact
  - attack.t1485
  - attack.t1496
  - attack.t1489
logsource:
  product: azure
  service: activitylogs
detection:
  selection:
    operationName:
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/WRITE
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/DELETE
  condition: selection
falsepositives:
  - Kubernetes cluster being created or  deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  - Kubernetes cluster created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
  - id: 9541f321-7cba-4b43-80fc-fbd1fb922808
    type: derived

What it detects

This rule flags Azure Activity Log events where a Kubernetes Connected Cluster is created or deleted. Such changes can indicate provisioning activity or an attempt to disrupt containerized workloads. It relies on Activity Log telemetry matching MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/WRITE and MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/DELETE operation names.

Known false positives

  • Kubernetes cluster being created or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  • Kubernetes cluster created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.