Kubernetes Audit: RoleBinding/ClusterRoleBinding Created or Modified via RBAC API

Alerts on Kubernetes RBAC RoleBinding/ClusterRoleBinding create or update actions seen in audit logs.

FreeUnreviewedSigmamediumv1
title: "Kubernetes Audit: RoleBinding/ClusterRoleBinding Created or Modified via RBAC API"
id: 14587918-9646-4182-8c8f-5be5316869d4
related:
  - id: 0322d9f2-289a-47c2-b5e1-b63c90901a3e
    type: similar
  - id: 10b97915-ec8d-455f-a815-9a78926585f6
    type: derived
status: test
description: This rule flags Kubernetes audit events where RoleBinding or ClusterRoleBinding objects are created or changed using RBAC API verbs. Attackers may use these modifications to alter permissions and escalate privileges by granting additional access through bindings. It relies on Kubernetes API audit telemetry capturing the target object reference (apiGroup and resource) and the operation verb.
references:
  - https://kubernetes.io/docs/reference/config-api/apiserver-audit.v1/
  - https://medium.com/@seifeddinerajhi/kubernetes-rbac-privilege-escalation-exploits-and-mitigations-26c07629eeab
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/kubernetes/audit/kubernetes_audit_rolebinding_modification.yml
author: kelnage, Huntrule Team
date: 2024-07-11
tags:
  - attack.privilege-escalation
logsource:
  product: kubernetes
  service: audit
detection:
  selection:
    objectRef.apiGroup: rbac.authorization.k8s.io
    objectRef.resource:
      - clusterrolebindings
      - rolebindings
    verb:
      - create
      - delete
      - patch
      - replace
      - update
  condition: selection
falsepositives:
  - Modifying a Kubernetes Rolebinding may need to be done by a system administrator.
  - Automated processes may need to take these actions and may need to be filtered.
level: medium
license: DRL-1.1

What it detects

This rule flags Kubernetes audit events where RoleBinding or ClusterRoleBinding objects are created or changed using RBAC API verbs. Attackers may use these modifications to alter permissions and escalate privileges by granting additional access through bindings. It relies on Kubernetes API audit telemetry capturing the target object reference (apiGroup and resource) and the operation verb.

Known false positives

  • Modifying a Kubernetes Rolebinding may need to be done by a system administrator.
  • Automated processes may need to take these actions and may need to be filtered.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.