LoFP LoFP / eks cluster created or deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.

Techniques

Sample rules

AWS EKS Cluster Created or Deleted

Description

Identifies when an EKS cluster is created or deleted.

Detection logic

condition: selection
selection:
  eventName:
  - CreateCluster
  - DeleteCluster
  eventSource: eks.amazonaws.com