Account Manipulation: Additional Container Cluster Roles T1098.006
Tactics: Persistence, Privilege Escalation
An adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a container orchestration system. For example, an adversary with sufficient permissions may create a RoleBinding or a ClusterRoleBinding to bind a Role or ClusterRole to a Kubernetes account. Where attribute-based access control (ABAC) is in use, an adversary with sufficient permissions may modify a Kubernetes ABAC policy to give the target account additional permissions. This account modification may immediately follow Create Account or other malicious account activity. Adversaries may also modify existing Valid Accounts that they have compromised.
Authoring guide
These 24 rules share fields, values, and exclusions.
Fields filtered most (42 distinct)
These fields appear most often in rule filters.
Top indicator values (159 distinct)
These values appear most often in rule predicates.
Exclusions (48 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Elastic 24 rules
- AWS EKS Access Entry Created Then Deleted by Same Identity
- AWS EKS Access Entry Granted Cluster Admin Policy
- AWS EKS Access Entry Modified
- Azure Kubernetes Services (AKS) Kubernetes Rolebindings Created
- EKS Authentication Configuration Modified
- GKE Certificate Signing Request API Client Signer Requested
- GKE Certificate Signing Request for Privileged Identity
- GKE Certificate Signing Request Self-Approved
- GKE Client Certificate Signing Request Created or Approved
- GKE Cluster-Admin Role Binding Created or Modified
- GKE Creation of a RoleBinding Referencing a ServiceAccount
- GKE Creation or Modification of Sensitive Role
- GKE RBAC Wildcard Elevation on Existing Role
- GKE Sensitive RBAC Change Followed by Workload Modification
- GKE Service Account Modified RBAC Objects
- GKE Unusual Sensitive Workload Modification
- Kubernetes Client Certificate Signing Request Created or Approved
- Kubernetes Cluster-Admin Role Binding Created
- Kubernetes Creation of a RoleBinding Referencing a ServiceAccount
- Kubernetes Creation or Modification of Sensitive Role
- Kubernetes RBAC Wildcard Elevation on Existing Role
- Kubernetes Sensitive RBAC Change Followed by Workload Modification
- Kubernetes Service Account Modified RBAC Objects
- Unusual Kubernetes Sensitive Workload Modification