Kubernetes RBAC RoleBinding Created or Modified via Audit Events

Alerts on Kubernetes RBAC RoleBinding/ClusterRoleBinding create or update actions seen in audit logs.

FreeReviewedSigma · Medium · v5
Product
kubernetes
Service
audit
Author
kelnage (SigmaHQ), DRL 1.1
Published
2024-07-11
Updated
2026-07-31

What it detects

This rule flags Kubernetes audit events where a RoleBinding or ClusterRoleBinding is created or modified. Attackers may change RBAC bindings to grant additional permissions or persistence within a cluster. The detection relies on Kubernetes audit telemetry that includes the RBAC API group, the bound resource type, and the HTTP verb indicating the operation.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.