Kubernetes Audit: RoleBinding/ClusterRoleBinding Created or Modified via RBAC API
Alerts on Kubernetes RBAC RoleBinding/ClusterRoleBinding create or update actions seen in audit logs.
FreeUnreviewedSigmamediumv1
kubernetes-audit-rolebinding-clusterrolebinding-created-or-modified-via-rbac-api-10b97915
title: "Kubernetes Audit: RoleBinding/ClusterRoleBinding Created or Modified via RBAC API"
id: 14587918-9646-4182-8c8f-5be5316869d4
related:
- id: 0322d9f2-289a-47c2-b5e1-b63c90901a3e
type: similar
- id: 10b97915-ec8d-455f-a815-9a78926585f6
type: derived
status: test
description: This rule flags Kubernetes audit events where RoleBinding or ClusterRoleBinding objects are created or changed using RBAC API verbs. Attackers may use these modifications to alter permissions and escalate privileges by granting additional access through bindings. It relies on Kubernetes API audit telemetry capturing the target object reference (apiGroup and resource) and the operation verb.
references:
- https://kubernetes.io/docs/reference/config-api/apiserver-audit.v1/
- https://medium.com/@seifeddinerajhi/kubernetes-rbac-privilege-escalation-exploits-and-mitigations-26c07629eeab
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/kubernetes/audit/kubernetes_audit_rolebinding_modification.yml
author: kelnage, Huntrule Team
date: 2024-07-11
tags:
- attack.privilege-escalation
logsource:
product: kubernetes
service: audit
detection:
selection:
objectRef.apiGroup: rbac.authorization.k8s.io
objectRef.resource:
- clusterrolebindings
- rolebindings
verb:
- create
- delete
- patch
- replace
- update
condition: selection
falsepositives:
- Modifying a Kubernetes Rolebinding may need to be done by a system administrator.
- Automated processes may need to take these actions and may need to be filtered.
level: medium
license: DRL-1.1
What it detects
This rule flags Kubernetes audit events where RoleBinding or ClusterRoleBinding objects are created or changed using RBAC API verbs. Attackers may use these modifications to alter permissions and escalate privileges by granting additional access through bindings. It relies on Kubernetes API audit telemetry capturing the target object reference (apiGroup and resource) and the operation verb.
Known false positives
- Modifying a Kubernetes Rolebinding may need to be done by a system administrator.
- Automated processes may need to take these actions and may need to be filtered.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.