Techniques
Sample rules
GKE Pod Exec Sensitive File or Credential Path Access
- source: elastic
- technicques:
- T1552
- T1609
Description
Detects successful GKE pod exec sessions where the executed command references high-value host or in-cluster paths: mounted service account or platform tokens, kubelet and control-plane configuration areas, host identity stores, root or home credential directories, common private-key and keystore extensions, process environment dumps, and configuration filenames suggestive of embedded secrets. Attackers with pods/exec often use these one-liners to steal credentials before lateral movement or privilege escalation. A narrow exclusion ignores benign resolv.conf reads. GKE records the command in gcp.audit.labels.command.gke.io/command when an explicit command is passed to exec.
Detection logic
data_stream.dataset:gcp.audit and service.name:"k8s.io" and event.outcome:success and
event.type:start and
event.action:("io.k8s.core.v1.pods.exec.create" or "io.k8s.core.v1.pods.exec.get") and
gcp.audit.labels.command.gke.io/command:(
(
*.jks* or *.key* or *.keystore* or *.p12* or *.pem* or
*/etc/kubernetes/* or */etc/passwd* or */etc/shadow* or */etc/sudoers* or
*/home/*/.aws* or */home/*/.azure* or */home/*/.config/gcloud* or */home/*/.kube* or */home/*/.ssh* or
*/proc/*/environ* or
*/root/.aws* or */root/.azure* or */root/.config/gcloud* or */root/.kube* or */root/.ssh* or
*/var/lib/kubelet/* or */var/run/secrets/* or
*/etc/*.conf* and (*credential* or *key* or *password* or *secret* or *token*)
) and not */etc/resolv.conf*
)