GCP Kubernetes audit events: Admission webhook configuration creates/updates

Flags GCP Kubernetes audit events indicating mutating/validating admission webhook configuration create/patch/replace activity.

FreeReviewedSigma · Medium · v4
Product
gcp
Service
gcp.audit
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-11-25
Updated
2026-07-31

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule identifies Kubernetes admission webhook configuration changes in Google Cloud by matching audit method names under admissionregistration.k8s.io for mutating and validating webhooks. Attackers can leverage these webhooks to intercept or modify API requests, enabling persistence, stealthy execution, and potential credential or secret capture. Telemetry is based on GCP audit log method_name values corresponding to create, patch, or replace operations on mutatingwebhookconfigurations or validatingwebhookconfigurations.

Related detections9 linkedT1078 — drag to rearrange
Kubernetes API Audit: Admission Webhook Configuration Modified
Azure Activity Logs: Kubernetes AdmissionRegistration webhook configuration writes
Malicious SD-WAN Compromise Credential Theft via loot_run.sh
Possible Next.js Middleware Auth Bypass via X-Middleware-Subrequest Header (CVE-2025-29927)
Possible SSRF via VMware Workspace One Access instanceHealth CVE-2021-22056
Suspicious Brutforce with Denied Access Due to Account Restrictions Policies (via security)
Suspicious Success Login Attempt on a Windows OpenSSH Server (via security)
Suspicious SQL Server - Connection Attempt Using a Disabled Account (via application)
Suspicious Lateral Movement Detection - Based on "special Groups" Feature (via security)
GCP Kubernetes audit events: Admission webhook configuration creates/updates
Pivot detection · T1078 · 9 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.