Update azure_kubernetes_cronjob.yml

This commit is contained in:
Austin Songer
2021-11-22 22:45:35 -06:00
committed by GitHub
parent 253ec56d1c
commit 70d1e6d0f3
@@ -15,10 +15,13 @@ logsource:
detection:
selection1:
properties.message: MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/BATCH/CRONJOBS/WRITE
selection2:
properties.message: MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/BATCH/JOBS/WRITE
selection3:
properties.message: MICROSOFT.CONTAINERSERVICE/MANAGEDCLUSTERS/BATCH/CRONJOBS/WRITE
selection4:
properties.message: ICROSOFT.CONTAINERSERVICE/MANAGEDCLUSTERS/BATCH/JOBS/WRITE
condition: selection1
condition: selection1 or selection2 or selection3 or selection4
level: medium
tags:
- attack.persistence