Azure Kubernetes Service Activity Logs: Secret/ConfigMap Write or Delete
Alerts on Azure AKS activity log operations that write or delete Kubernetes ConfigMaps or Secrets.
FreeUnreviewedSigmamediumv1
azure-kubernetes-service-activity-logs-secret-configmap-write-or-delete-7ee0b4aa
title: "Azure Kubernetes Service Activity Logs: Secret/ConfigMap Write or Delete"
id: ae89d6da-e08e-465e-a240-66f826edaf29
status: test
description: This rule flags Azure Activity Log events where a Kubernetes connected cluster writes or deletes a ConfigMap or Secret. Attackers may modify or remove these resources to tamper with application configuration, steal sensitive data, or disrupt workloads. It relies on Azure Activity Log telemetry for matching MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS operations corresponding to ConfigMap/Secret write and delete actions.
references:
- https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
- https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
- https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
- https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_kubernetes_secret_or_config_object_access.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
- attack.impact
- attack.t1485
- attack.t1496
- attack.t1489
logsource:
product: azure
service: activitylogs
detection:
selection:
operationName:
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/CONFIGMAPS/WRITE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/CONFIGMAPS/DELETE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SECRETS/WRITE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SECRETS/DELETE
condition: selection
falsepositives:
- Sensitive objects may be accessed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Sensitive objects accessed from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
- id: 7ee0b4aa-d8d4-4088-b661-20efdf41a04c
type: derived
What it detects
This rule flags Azure Activity Log events where a Kubernetes connected cluster writes or deletes a ConfigMap or Secret. Attackers may modify or remove these resources to tamper with application configuration, steal sensitive data, or disrupt workloads. It relies on Azure Activity Log telemetry for matching MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS operations corresponding to ConfigMap/Secret write and delete actions.
Known false positives
- Sensitive objects may be accessed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Sensitive objects accessed from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.