Kubernetes Deployment Deleted via Kubernetes API Audit Logs

Alerts when Kubernetes audit logs show a delete action against deployments.

FreeReviewedSigma · Low · v5
Product
kubernetes
Category
application
Author
Leo Tsaousis (@laripping) (SigmaHQ), DRL 1.1
Published
2024-03-26
Updated
2026-07-31

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule identifies Kubernetes API audit events where a delete operation targets the deployments resource in a cluster. Deleting deployments can disrupt workloads and is a common step in impact-driven activity. Detection relies on Kubernetes audit log records capturing the request verb and the affected object reference.

Related detections3 linkedT1498 — drag to rearrange
Malicious Simps Botnet Infection Marker File Creation (via file_event)
OpenCanary NTP Monlist Request Observed
Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Kubernetes Deployment Deleted via Kubernetes API Audit Logs
Pivot detection · T1498 · 3 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.