Malicious Direct etcd Write to Kubernetes Registry via ETCDCTL_API (via process_creation)

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-06-18
Updated
2026-08-28

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects direct writes to the Kubernetes object store held in etcd by invoking etcdctl v3 against the /registry key space. Attackers who compromise etcd use this to inject privileged pods or hidden namespace resources that never pass through the kube-apiserver. Bypassing the API server evades admission controllers and audit logging while granting node and cluster takeover.

Related detections9 linkedT1611 — drag to rearrange
Malicious Privileged Container Creation in Kubernetes (via audit)
Suspicious Command Execution Inside a Kubernetes Pod (via audit)
Malicious Docker Socket Access via Curl Unix Socket
Suspicious Cgroup release_agent Abuse for Container Escape
Malicious Container Escape via core_pattern Hijack (via process_creation)
Kubernetes audit log signals potential tool and shell enumeration/execution activity
Kubernetes Pod Created With hostPath Volume Mount
Kubernetes Pod exec via API creates exec subresource requests
Kubernetes Audit: Sidecar Injection via kubectl patch to Deployments
Malicious Direct etcd Write to Kubernetes Registry via ETCDCTL_API (via process_creation)
Pivot detection · T1611 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.