This repository was archived by the owner on Sep 16, 2026. It is now read-only.
forked from panther-labs/panther-analysis
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathkubernetes.yml
More file actions
38 lines (38 loc) · 1.57 KB
/
Copy pathkubernetes.yml
File metadata and controls
38 lines (38 loc) · 1.57 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
AnalysisType: pack
PackID: PantherManaged.Kubernetes.Core
DisplayName: "Panther Core Kubernetes Pack"
Description: This is a group of detections that act on Kubernetes logs sourced from Amazon EKS.
PackDefinition:
IDs:
# Kubernetes scheduled queries and rules
- Kubernetes.CronJobCreatedOrModified
- Kubernetes.DaemonSetDeployed
- Kubernetes.IOCActivity
- Kubernetes.NewAdmissionControllerCreated
- Kubernetes.OverlyPermissivePod
- Kubernetes.PodAttachedHostNetwork
- Kubernetes.PodCreatedDefaultNameSpace
- Kubernetes.PodHostPathVolumeMount
- Kubernetes.PodUsingHostPIDNamespace
- Kubernetes.PodUsingIPCNamespace
- Kubernetes.PrivilegedPodCreated
- Kubernetes.SecretEnumeration
- Kubernetes.ServiceTypeNodePortDeployed
- Kubernetes.UnauthenticatedAPIRequest
- Kubernetes.UnauthorizedPodExecution
# Queries
- IOC Activity in K8 Control Plane
- Kubernetes Cron Job Created or Modified
- Kubernetes Pod Created in Pre-Configured or Default Name Spaces
- Kubernetes Service with Type Node Port Deployed
- New Admission Controller Created
- New DaemonSet Deployed to Kubernetes
- Pod Created or Modified Using the Host IPC Namespace
- Pod Created or Modified Using the Host PID Namespace
- Pod Created with Overly Permissive Linux Capabilities
- Pod attached to the Node Host Network
- Pod creation or modification to a Host Path Volume Mount
- Privileged Pod Created
- Secret Enumeration by a User
- Unauthenticated Kubernetes API Request
- Unauthorized Kubernetes Pod Execution