GKE Pod Exec Sensitive File or Credential Path Access
editGKE Pod Exec Sensitive File or Credential Path Access
editDetects successful GKE pod exec sessions where the executed command references high-value host or in-cluster paths: mounted service account or platform tokens, kubelet and control-plane configuration areas, host identity stores, root or home credential directories, common private-key and keystore extensions, process environment dumps, and configuration filenames suggestive of embedded secrets. Attackers with pods/exec often use these one-liners to steal credentials before lateral movement or privilege escalation. A narrow exclusion ignores benign resolv.conf reads. GKE records the command in gcp.audit.labels.command.gke.io/command when an explicit command is passed to exec.
Rule type: query
Rule indices:
- logs-gcp.audit-*
Severity: high
Risk score: 73
Runs every: 5m
Searches indices from: now-6m (Date Math format, see also Additional look-back time)
Maximum alerts per execution: 100
References:
Tags:
- Domain: Cloud
- Domain: Kubernetes
- Data Source: GCP
- Data Source: GCP Audit Logs
- Data Source: Google Cloud Platform
- Use Case: Threat Detection
- Tactic: Credential Access
- Tactic: Execution
- Resources: Investigation Guide
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editTriage and analysis
Investigating GKE Pod Exec Sensitive File or Credential Path Access
This alert fires when a successful pods/exec API call includes a command matching sensitive path or filename
patterns. Review gcp.audit.labels.command.gke.io/command for the reconstructed command string.
Possible investigation steps
-
Identify the actor (
client.user.email), source IP, and user agent for the exec caller. -
Map
gcp.audit.resource_name(namespace/pod) to a workload owner, image, and change history. - Correlate adjacent activity from the same identity: secret reads, TokenRequest, RBAC writes, or additional execs.
- If host-level paths appear, determine whether the workload is privileged, uses hostPath, or runs on break-glass nodes.
False positive analysis
- Diagnostic images and vendor agents sometimes read kubeconfig-like or credential paths; baseline stable automation.
- Training containers that deliberately demonstrate passwd reads can trigger; scope exceptions to those namespaces.
Response and remediation
- If malicious, end the exec session, isolate the pod or node, rotate credentials that could have been read, and tighten pods/exec RBAC and admission controls.
Setup
editThe GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.
Rule query
editdata_stream.dataset:gcp.audit and service.name:"k8s.io" and event.outcome:success and
event.type:start and
event.action:("io.k8s.core.v1.pods.exec.create" or "io.k8s.core.v1.pods.exec.get") and
gcp.audit.labels.command.gke.io/command:(
(
*.jks* or *.key* or *.keystore* or *.p12* or *.pem* or
*/etc/kubernetes/* or */etc/passwd* or */etc/shadow* or */etc/sudoers* or
*/home/*/.aws* or */home/*/.azure* or */home/*/.config/gcloud* or */home/*/.kube* or */home/*/.ssh* or
*/proc/*/environ* or
*/root/.aws* or */root/.azure* or */root/.config/gcloud* or */root/.kube* or */root/.ssh* or
*/var/lib/kubelet/* or */var/run/secrets/* or
*/etc/*.conf* and (*credential* or *key* or *password* or *secret* or *token*)
) and not */etc/resolv.conf*
)
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Credential Access
- ID: TA0006
- Reference URL: https://attack.mitre.org/tactics/TA0006/
-
Technique:
- Name: Unsecured Credentials
- ID: T1552
- Reference URL: https://attack.mitre.org/techniques/T1552/
-
Sub-technique:
- Name: Credentials In Files
- ID: T1552.001
- Reference URL: https://attack.mitre.org/techniques/T1552/001/
-
Sub-technique:
- Name: Container API
- ID: T1552.007
- Reference URL: https://attack.mitre.org/techniques/T1552/007/
-
Tactic:
- Name: Execution
- ID: TA0002
- Reference URL: https://attack.mitre.org/tactics/TA0002/
-
Technique:
- Name: Container Administration Command
- ID: T1609
- Reference URL: https://attack.mitre.org/techniques/T1609/