Kubernetes Audit: Listing Secrets (Enumeration of Secret Resources)

Alerts on Kubernetes audit requests that list the secrets resource, consistent with secret enumeration.

FreeReviewedSigma · Low · v5
Product
kubernetes
Category
application
Author
Leo Tsaousis (@laripping) (SigmaHQ), DRL 1.1
Published
2024-03-26
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Kubernetes API audit events where an actor uses the list verb against the secrets resource, indicating attempted enumeration of stored credentials or configuration. Attackers often enumerate secrets to identify valuable data before attempting access or extraction. The detection relies on Kubernetes audit telemetry that records the requested verb and the target resource type.

Related detections5 linkedT1552.007 — drag to rearrange
Suspicious Kubernetes Secret Enumeration via kubectl
Malicious EKS Pod Identity Credential Theft via Link-Local Endpoint
Kubernetes API Audit: Admission Webhook Configuration Modified
GCP Kubernetes audit events: Admission webhook configuration creates/updates
Azure Activity Logs: Kubernetes AdmissionRegistration webhook configuration writes
Kubernetes Audit: Listing Secrets (Enumeration of Secret Resources)
Pivot detection · T1552.007 · 5 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.