Query Details

Azure Kubernetes Service Pod Accessing Instance Metadata API

Query

let Lookback = 1d;
let AllowedNamespaces = dynamic(["kube-system", "gatekeeper-system", "calico-system"]);
let AksEgressRanges = dynamic(["20.0.0.10/32", "10.0.0.0/8"]);   // LB/NAT Gateway Outbound IPs + interne Ranges
let ClusterIdentities = datatable(ClusterResourceId:string, IdentityObjectId:string, IdentityType:string)[
    "/subscriptions/<sub>/resourcegroups/<rg>/providers/microsoft.containerservice/managedclusters/<aks>", "<kubelet-mi-objectid>", "Kubelet",
    "/subscriptions/<sub>/resourcegroups/<rg>/providers/microsoft.containerservice/managedclusters/<aks>", "<workload-mi-objectid>", "WorkloadIdentity"
];   // besser als Watchlist pflegen
let PodTokenAccess = CloudProcessEvents
| where Timestamp > ago(Lookback)
| where isnotempty(KubernetesPodName) and KubernetesNamespace !in (AllowedNamespaces)
| extend Cmd = tolower(ProcessCommandLine)
| where (Cmd has "169.254.169.254" and Cmd has_any ("metadata/identity", "oauth2"))
     or Cmd has "azure-identity-token"
| summarize FirstPodAccess = min(Timestamp),
            Pods = make_set(strcat(KubernetesNamespace, "/", KubernetesPodName), 20),
            TokenCmds = make_set(ProcessCommandLine, 10)
    by ClusterResourceId = tolower(AzureResourceId);
AzureActivity
| where TimeGenerated > ago(Lookback)
| join kind=inner (ClusterIdentities | extend ClusterResourceId = tolower(ClusterResourceId))
    on $left.Caller == $right.IdentityObjectId
| where isnotempty(CallerIpAddress) and not(ipv4_is_in_any_range(CallerIpAddress, AksEgressRanges))
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
            Operations = make_set(OperationNameValue, 30),
            TargetResources = dcount(_ResourceId),
            CallerIps = make_set(CallerIpAddress, 10)
    by Caller, IdentityType, ClusterResourceId
| join kind=leftouter PodTokenAccess on ClusterResourceId
| extend Severity = iff(isnotempty(Pods) and FirstPodAccess <= LastSeen, "High", "Medium")

About this query

Azure Kubernetes Service Pod Accessing Instance Metadata API

Query Information

MITRE ATT&CK Technique(s)

Technique IDTitleLink
T1552.005Cloud Instance Metadata APIhttps://attack.mitre.org/techniques/T1552/005
T1528Steal Application Access Tokenhttps://attack.mitre.org/techniques/T1528

Description

This rule detects potentially malicious behavior where a Kubernetes pod in an AKS cluster attempts to access the Azure Instance Metadata Service (IMDS) at 169.254.169.254 or specifically requests Azure identity tokens. It then correlates this with Azure Activity logs to identify if the associated Managed Identity is performing operations from unauthorized IP addresses, signaling potential token theft or unauthorized use of cloud credentials.

Author <Optional>

Defender XDR

Explanation

This query is designed to detect potentially malicious activities in an Azure Kubernetes Service (AKS) environment. Here's a simplified breakdown of what it does:

  1. Purpose: The query aims to identify Kubernetes pods that might be trying to access sensitive metadata or identity tokens from the Azure Instance Metadata Service (IMDS). This is a common technique used by attackers to steal credentials or tokens.

  2. Key Components:

    • Lookback Period: The query examines data from the past day (1d).
    • Allowed Namespaces: It excludes certain Kubernetes namespaces (like kube-system) from the analysis, as these are typically legitimate and necessary for system operations.
    • Egress IP Ranges: It defines IP ranges that are considered normal for outbound traffic from the AKS cluster.
    • Cluster Identities: It maintains a list of managed identities associated with the AKS cluster for correlation purposes.
  3. Detection Logic:

    • Pod Token Access: The query looks for processes within Kubernetes pods that attempt to access the IMDS or request Azure identity tokens. It captures the first time such access is detected, the pods involved, and the commands used.
    • Azure Activity Correlation: It checks Azure Activity logs to see if any operations are performed by these identities from IP addresses outside the defined egress ranges, which could indicate unauthorized access.
  4. Severity Assessment:

    • The query assigns a severity level to the detected activity. If a pod is found accessing tokens and this activity correlates with unauthorized IP usage, the severity is marked as "High". Otherwise, it's marked as "Medium".

In summary, this query helps identify suspicious access patterns in AKS that could indicate an attempt to steal or misuse cloud credentials, allowing security teams to take appropriate action.