Query Details

Suspicious Credential Access And Process Memory Enumeration In Kubernetes Containers

Query

let Lookback = 1d;
let AllowedImages = dynamic(["datadog", "dynatrace", "newrelic", "falco", "otel", "fluent", "ama-logs", "omsagent", "microsoft-defender"]);
CloudProcessEvents
| where Timestamp > ago(Lookback)
| where isnotempty(KubernetesPodName) or ContainerName == "host"
| where not(ContainerImageName has_any (AllowedImages))
| extend Cmd = tolower(ProcessCommandLine), P = tolower(ProcessName)
| extend Technique = case(
    Cmd matches regex @"/proc/(\d+|\*)/environ", "ProcEnvironOtherProcess",
    Cmd matches regex @"/proc/(\d+|\*)/root/", "ProcRootTraversal",
    Cmd matches regex @"/proc/(\d+|\*)/(mem|maps)\b" or P in ("gdb", "gcore"), "ProcessMemoryAccess",
    Cmd has_any ("/etc/kubernetes/azure.json", "/etc/kubernetes/kubelet.conf", "/var/lib/kubelet/kubeconfig",
                 "/var/lib/kubelet/pki", "/etc/kubernetes/pki", "/etc/kubernetes/certs"), "NodeCredentialFiles",
    Cmd has_any (".kube/config", ".azure/msal_token_cache", ".azure/accesstokens.json", ".docker/config.json",
                 ".aws/credentials", ".git-credentials"), "UserCredentialFiles",
    Cmd matches regex @"\b(env|printenv)\b.*\|\s*e?grep\b.*(key|secret|token|pass)", "EnvSecretGrep",
    "")
| where isnotempty(Technique)
| summarize FirstSeen = min(Timestamp), LastSeen = max(Timestamp),
            Techniques = make_set(Technique), Commands = make_set(ProcessCommandLine, 20),
            Parents = make_set(ParentProcessName, 10)
    by AzureResourceId, KubernetesNamespace, KubernetesPodName, ContainerName, ContainerImageName, HostName
| extend Severity = case(set_has_element(Techniques, "NodeCredentialFiles") or set_has_element(Techniques, "ProcRootTraversal"), "High",
                         array_length(Techniques) >= 2, "High",
                         "Medium")
| order by Severity asc, FirstSeen desc

About this query

Suspicious Credential Access and Process Memory Enumeration in Kubernetes Containers*

Query Information

MITRE ATT&CK Technique(s)

Technique IDTitleLink
T1552Unsecured Credentialshttps://attack.mitre.org/techniques/T1552
T1555Credentials from Password Storeshttps://attack.mitre.org/techniques/T1555
T1003.007Proc Filesystemvhttps://attack.mitre.org/techniques/T1003/007
T1083File and Directory Discoveryhttps://attack.mitre.org/techniques/T1083

Description

Detects anomalous shell process execution originating from common web application processes within a containerized environment. The rule uses behavioral indicators such as parent-child process relationships, network-related command execution, file system reconnaissance, and suspicious utility usage to calculate a risk score for newly observed or suspicious shell activity.

Author <Optional>

Defender XDR

Explanation

This query is designed to detect suspicious activities related to credential access and process memory enumeration within Kubernetes containers. Here's a simplified breakdown of what the query does:

  1. Time Frame: It looks at cloud process events from the last day (Lookback = 1d).

  2. Filter Criteria:

    • It focuses on events from Kubernetes pods or containers named "host".
    • It excludes events from containers using specific allowed images (like "datadog", "dynatrace", etc.).
  3. Process Analysis:

    • It examines the command line and process names, converting them to lowercase for consistency.
    • It identifies specific suspicious activities (techniques) based on patterns in the command line or process names. These include:
      • Accessing other processes' environment variables or memory.
      • Traversing the root directory of other processes.
      • Accessing sensitive credential files related to Kubernetes, Azure, Docker, AWS, etc.
      • Using commands to search for environment variables containing sensitive information like keys or tokens.
  4. Technique Identification: It assigns a technique label to each suspicious activity detected.

  5. Event Summarization:

    • It summarizes the events by resource ID, namespace, pod name, container name, image name, and host name.
    • It records the first and last time the activity was seen, the techniques used, the commands executed, and the parent processes involved.
  6. Severity Assessment:

    • It assigns a severity level to each event based on the techniques detected:
      • "High" severity for certain techniques or if multiple techniques are detected.
      • "Medium" severity for other cases.
  7. Output: The results are ordered by severity and the time the activity was first seen, with high-severity events prioritized.

Overall, this query helps identify potentially malicious activities in Kubernetes environments by analyzing process behaviors and flagging those that match known suspicious patterns.