From 23d5ed9d23d8a4e1b43fed2b0cefbf1b879f93c2 Mon Sep 17 00:00:00 2001 From: Austin Songer Date: Mon, 9 Aug 2021 22:06:56 -0500 Subject: [PATCH] Create gcp_kubernetes_secrets_modified_or_deleted.yml --- ...kubernetes_secrets_modified_or_deleted.yml | 24 +++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 rules/cloud/gcp_kubernetes_secrets_modified_or_deleted.yml diff --git a/rules/cloud/gcp_kubernetes_secrets_modified_or_deleted.yml b/rules/cloud/gcp_kubernetes_secrets_modified_or_deleted.yml new file mode 100644 index 000000000..8b78f9936 --- /dev/null +++ b/rules/cloud/gcp_kubernetes_secrets_modified_or_deleted.yml @@ -0,0 +1,24 @@ +title: Google Cloud Kubernetes Secrets Modified or Deleted +id: 2f0bae2d-bf20-4465-be86-1311addebaa3 +description: Identifies when the Secrets are Modified or Deleted. +author: Austin Songer +status: experimental +date: 2021/08/09 +references: + - https://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging +logsource: + service: gcp.audit +detection: + selection: + eventName: + - io.k8s.core.v*.secrets.create + - io.k8s.core.v*.secrets.update + - io.k8s.core.v*.secrets.patch + - io.k8s.core.v*.secrets.delete + condition: selection +level: medium +tags: + - attack.credential_access +falsepositives: + - Secrets being modified or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. + - Secrets modified or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.