Query Details

Anomalous Kubernetes Service Account API Activity

Query

let Lookback = 14d;
let DetectWindow = 1h;
let SAAudit = CloudAuditEvents
| where Timestamp > ago(Lookback)
| where DataSource =~ "Kubernetes Audit"
| extend User = tostring(RawEventData.user.username)
| where User startswith "system:serviceaccount:"
| extend SourceIp = tostring(RawEventData.sourceIPs[0]),
         UserAgent = tostring(RawEventData.userAgent),
         UAFamily = tolower(tostring(split(tostring(RawEventData.userAgent), "/")[0])),
         Verb = tolower(tostring(RawEventData.verb)),
         Resource = tolower(tostring(RawEventData.objectRef.resource)),
         Code = toint(RawEventData.responseStatus.code);
let Baseline = SAAudit
| where Timestamp < ago(DetectWindow)
| summarize KnownIps = make_set(SourceIp, 1000), KnownUA = make_set(UAFamily, 100) by User, AzureResourceId;
SAAudit
| where Timestamp >= ago(DetectWindow)
| join kind=inner Baseline on User, AzureResourceId
| extend NewIp = not(set_has_element(KnownIps, SourceIp)),
         NewUA = not(set_has_element(KnownUA, UAFamily)),
         PublicIp = not(ipv4_is_private(SourceIp)),
         HackerUA = UAFamily has_any ("kubectl", "curl", "python", "go-http-client", "wget", "postman")
| where NewIp
| summarize FirstSeen = min(Timestamp), LastSeen = max(Timestamp), Requests = count(),
            Actions = make_set(strcat(Verb, " ", Resource), 30),
            Forbidden = countif(Code == 403),
            UserAgents = make_set(UserAgent, 5),
            NewUA = max(toint(NewUA)), PublicIp = max(toint(PublicIp)), HackerUA = max(toint(HackerUA))
    by User, SourceIp, AzureResourceId
| extend Score = 2 + NewUA * 2 + PublicIp * 3 + HackerUA * 2 + iff(Forbidden > 0, 1, 0)
| where Score >= 4
| order by Score desc

About this query

Anomalous Kubernetes Service Account API Activity

Query Information

MITRE ATT&CK Technique(s)

Technique IDTitleLink
T1078.004Cloud Accountshttps://attack.mitre.org/techniques/T1078/004
T1133External Remote Serviceshttps://attack.mitre.org/techniques/T1133
T1609Container Administration Commandhttps://attack.mitre.org/techniques/T1609

Description

This rule detects potentially unauthorized or anomalous activity from Kubernetes service accounts by baselining historical source IP and user agent patterns. It triggers when a service account performs actions from a new IP address or using a new user agent string, especially when those identifiers match known adversarial tooling or originate from non-private IP addresses.

Author <Optional>

Defender XDR

Explanation

This query is designed to detect unusual or potentially unauthorized activities performed by Kubernetes service accounts. Here's a simplified breakdown of what the query does:

  1. Time Frame: It looks at Kubernetes audit logs from the past 14 days but focuses on activities within the last hour.

  2. Data Filtering: It filters the logs to only include actions performed by service accounts, identified by usernames starting with "system:serviceaccount:".

  3. Data Extraction: For each log entry, it extracts details such as the source IP address, user agent string, HTTP verb, resource accessed, and response status code.

  4. Baseline Creation: It establishes a baseline of known IP addresses and user agent patterns for each service account by analyzing historical data (excluding the last hour).

  5. Anomaly Detection: It checks if recent activities (within the last hour) involve:

    • A new IP address not seen before for that service account.
    • A new user agent string not seen before.
    • A public IP address (not private).
    • User agent strings associated with known hacking tools (e.g., "kubectl", "curl").
  6. Scoring: Each detected anomaly is scored based on:

    • New user agent (adds 2 points).
    • Public IP address (adds 3 points).
    • Known hacking tool user agent (adds 2 points).
    • Forbidden access attempts (adds 1 point if any).
  7. Alert Generation: It generates alerts for activities with a score of 4 or higher, indicating potentially suspicious behavior. The results are sorted by score in descending order to prioritize the most suspicious activities.

In summary, this query helps identify potentially malicious activities by detecting deviations from normal behavior patterns of Kubernetes service accounts, focusing on new IPs, user agents, and known hacking tools.