Unsecured Credentials: Container API T1552.007
Tactic: Credential Access
Adversaries may gather credentials via APIs within a containers environment. APIs in these environments, such as the Docker API and Kubernetes APIs, allow a user to remotely manage their container resources and cluster components.
Events covered
1 catalog event is tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
Authoring guide
These 32 rules share fields, values, and exclusions.
Fields filtered most (48 distinct)
These fields appear most often in rule filters.
Top indicator values (261 distinct)
These values appear most often in rule predicates.
Exclusions (97 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 4 rules
- Azure Kubernetes Admission Controller
- Google Cloud Kubernetes Admission Controller
- Kubernetes Admission Controller Modification
- Kubernetes Secrets Enumeration
Elastic 20 rules
- Azure AKS Secret get or list with Suspicious User Agent
- Azure Arc Cluster Credential Access by Identity from Unusual Source
- Azure Service Principal Sign-In Followed by Arc Cluster Credential Access
- GKE Pod Exec Sensitive File or Credential Path Access
- GKE Rapid Secret GET Activity Against Multiple Objects
- GKE Secret Access from Node or Denied Service Account
- GKE Secret Access via Unusual User Agent
- GKE Secret get or list with Suspicious User Agent
- GKE Secrets List from Unusual Source AS Organization
- GKE Unusual Service Account Secret Access via New User Agent
- Kubernetes Direct API Request via Curl or Wget
- Kubernetes Pod Exec Sensitive File or Credential Path Access
- Kubernetes Rapid Secret GET Activity Against Multiple Objects
- Kubernetes Secret Access via Unusual User Agent
- Kubernetes Secret Get or List from Node or Pod Service Account
- Kubernetes Secret Get or List with Suspicious User Agent
- Kubernetes Secret or ConfigMap Access via Azure Arc Proxy
- Kubernetes Secrets List Across Cluster or Sensitive Namespaces
- Kubernetes Service Account Token Created via TokenRequest API
- Sensitive Identity File Open by Suspicious Process via Auditd
Splunk 4 rules
- Kubernetes Abuse of Secret by Unusual Location
- Kubernetes Abuse of Secret by Unusual User Agent
- Kubernetes Abuse of Secret by Unusual User Group
- Kubernetes Abuse of Secret by Unusual User Name