Azure Kubernetes Service Activity Logs: Secret/ConfigMap Write or Delete

Alerts on Azure AKS activity log operations that write or delete Kubernetes ConfigMaps or Secrets.

FreeUnreviewedSigmamediumv1
title: "Azure Kubernetes Service Activity Logs: Secret/ConfigMap Write or Delete"
id: ae89d6da-e08e-465e-a240-66f826edaf29
status: test
description: This rule flags Azure Activity Log events where a Kubernetes connected cluster writes or deletes a ConfigMap or Secret. Attackers may modify or remove these resources to tamper with application configuration, steal sensitive data, or disrupt workloads. It relies on Azure Activity Log telemetry for matching MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS operations corresponding to ConfigMap/Secret write and delete actions.
references:
  - https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
  - https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
  - https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
  - https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_kubernetes_secret_or_config_object_access.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
  - attack.impact
  - attack.t1485
  - attack.t1496
  - attack.t1489
logsource:
  product: azure
  service: activitylogs
detection:
  selection:
    operationName:
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/CONFIGMAPS/WRITE
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/CONFIGMAPS/DELETE
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SECRETS/WRITE
      - MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SECRETS/DELETE
  condition: selection
falsepositives:
  - Sensitive objects may be accessed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Sensitive objects accessed from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
  - id: 7ee0b4aa-d8d4-4088-b661-20efdf41a04c
    type: derived

What it detects

This rule flags Azure Activity Log events where a Kubernetes connected cluster writes or deletes a ConfigMap or Secret. Attackers may modify or remove these resources to tamper with application configuration, steal sensitive data, or disrupt workloads. It relies on Azure Activity Log telemetry for matching MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS operations corresponding to ConfigMap/Secret write and delete actions.

Known false positives

  • Sensitive objects may be accessed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Sensitive objects accessed from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.