LoFP LoFP / operators and support tooling use ephemeral containers (kubectl debug) for legitimate troubleshooting. baseline expected users and exclude verified break-glass or platform identities after review.

Techniques

Sample rules

Azure AKS Ephemeral Container Added to Pod

Description

Detects an identity injecting an ephemeral (debug) container into a running AKS (Azure Kubernetes Service) pod via the pods/ephemeralcontainers subresource, excluding known AKS control-plane and platform identities. Ephemeral containers share the target pod’s namespaces and give stealthy interactive access to its processes and mounted secrets without creating a new pod. Coverage includes workload service accounts (system:serviceaccount:*), so a compromised in-cluster token used to attach a debug container is not excluded.

Detection logic

data_stream.dataset:azure.platformlogs and
  event.action:"Microsoft.ContainerService/managedClusters/diagnosticLogs/Read" and
  azure.platformlogs.category:("kube-audit" or "kube-audit-admin") and
  azure.platformlogs.properties.log.stage:"ResponseComplete" and
  azure.platformlogs.properties.log.objectRef.resource:"pods" and
  azure.platformlogs.properties.log.objectRef.subresource:"ephemeralcontainers" and
  azure.platformlogs.properties.log.verb:("update" or "patch") and
  not azure.platformlogs.properties.log.user.username:(
    system\:node\:* or "aksService" or "hcpService" or "readinessChecker" or
    system\:serviceaccount\:kube-system\:*
  )