Suspicious Command Execution Inside a Kubernetes Pod (via audit)

PremiumReviewedSigma · Medium · v1
Product
kubernetes
Service
audit
Author
HuntRule
Published
2026-09-04
Updated
2026-09-04

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a create request against the pods/exec subresource, which opens an interactive shell inside a running container, a technique attackers use for hands-on-keyboard access to a Kubernetes workload. Exec into pod is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting these requests surfaces interactive access to container workloads.

Related detections4 linkedT1609 — drag to rearrange
Malicious Direct etcd Write to Kubernetes Registry via ETCDCTL_API (via process_creation)
Kubernetes audit log signals potential tool and shell enumeration/execution activity
Kubernetes Pod exec via API creates exec subresource requests
Kubernetes Audit: Sidecar Injection via kubectl patch to Deployments
Suspicious Command Execution Inside a Kubernetes Pod (via audit)
Pivot detection · T1609 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.