LoFP LoFP / break-glass debugging or vendor diagnostics may cat credential-adjacent paths. baseline approved operators and automation identities, then expand client.user.email exclusions as needed.

Techniques

Sample rules

GKE Pod Exec Sensitive File or Credential Path Access

Description

Detects successful GKE pod exec sessions where the executed command references high-value host or in-cluster paths: mounted service account or platform tokens, kubelet and control-plane configuration areas, host identity stores, root or home credential directories, common private-key and keystore extensions, process environment dumps, and configuration filenames suggestive of embedded secrets. Attackers with pods/exec often use these one-liners to steal credentials before lateral movement or privilege escalation. A narrow exclusion ignores benign resolv.conf reads. GKE records the command in gcp.audit.labels.command.gke.io/command when an explicit command is passed to exec.

Detection logic

data_stream.dataset:gcp.audit and service.name:"k8s.io" and event.outcome:success and
event.type:start and
event.action:("io.k8s.core.v1.pods.exec.create" or "io.k8s.core.v1.pods.exec.get") and
gcp.audit.labels.command.gke.io/command:(
  (
    *.jks* or *.key* or *.keystore* or *.p12* or *.pem* or
    */etc/kubernetes/* or */etc/passwd* or */etc/shadow* or */etc/sudoers* or
    */home/*/.aws* or */home/*/.azure* or */home/*/.config/gcloud* or */home/*/.kube* or */home/*/.ssh* or
    */proc/*/environ* or
    */root/.aws* or */root/.azure* or */root/.config/gcloud* or */root/.kube* or */root/.ssh* or
    */var/lib/kubelet/* or */var/run/secrets/* or
    */etc/*.conf* and (*credential* or *key* or *password* or *secret* or *token*)
  ) and not */etc/resolv.conf*
)