Query Details

Unusual Access To Helm Secrets In Kubernetes

Query

let Lookback = 30d;
let DetectWindow = 1d;
let HelmSecrets = CloudAuditEvents
| where Timestamp > ago(Lookback)
| where DataSource =~ "Kubernetes Audit"
| extend Resource = tolower(tostring(RawEventData.objectRef.resource)),
         Verb = tolower(tostring(RawEventData.verb)),
         ObjName = tostring(RawEventData.objectRef.name),
         Namespace = tostring(RawEventData.objectRef.namespace),
         Actor = tostring(RawEventData.user.username),
         UserAgent = tostring(RawEventData.userAgent),
         SourceIp = tostring(RawEventData.sourceIPs[0]),
         Code = toint(RawEventData.responseStatus.code)
| where Resource == "secrets" and Verb == "get" and ObjName startswith "sh.helm.release.v1."
| where Code between (200 .. 299);
let Baseline = HelmSecrets
| where Timestamp < ago(DetectWindow)
| distinct Actor, AzureResourceId, Namespace;
HelmSecrets
| where Timestamp >= ago(DetectWindow)
| join kind=leftanti Baseline on Actor, AzureResourceId, Namespace
| extend UAFamily = tolower(tostring(split(UserAgent, "/")[0]))
| summarize FirstSeen = min(Timestamp), Releases = make_set(ObjName, 50), Namespaces = make_set(Namespace, 20),
            UserAgents = make_set(UserAgent, 5), SourceIps = make_set(SourceIp, 5),
            NonHelmClient = max(toint(not(UAFamily startswith "helm")))
    by Actor, AzureResourceId
| extend Severity = iff(NonHelmClient == 1 or array_length(Namespaces) > 1, "High", "Medium")

About this query

Unusual Access to Helm Secrets in Kubernetes*

Query Information

MITRE ATT&CK Technique(s)

Technique IDTitleLink
T1552.001Credentials in Fileshttps://attack.mitre.org/techniques/T1552/001
T1555Credentials from Password Storeshttps://attack.mitre.org/techniques/T1552

Description

Detects instances where an identity (user or service account) accesses Kubernetes secrets associated with Helm releases (prefixed with sh.helm.release.v1.) without a historical baseline for such activity. The rule flags potential unauthorized credential access in a containerized environment, with heightened severity for non-standard user agents or cross-namespace activity.

Author <Optional>

Defender XDR

Explanation

This query is designed to detect unusual access to Kubernetes secrets associated with Helm releases. Here's a simplified breakdown of what it does:

  1. Time Frame: It looks at Kubernetes audit logs over the past 30 days to establish a baseline of normal activity and focuses on the last day to detect unusual activity.

  2. Focus: It specifically targets access to secrets that are part of Helm releases, which are identified by names starting with "sh.helm.release.v1.".

  3. Normal vs. Unusual Activity:

    • Baseline: It creates a baseline of normal access patterns by identifying which users or service accounts have accessed these secrets in the past.
    • Detection: It then checks for any access in the last day that doesn't match this baseline, indicating potential unauthorized access.
  4. Additional Checks:

    • It examines the user agent to see if the access was made using a non-standard client (i.e., not using the Helm client).
    • It also checks if the access spans multiple namespaces, which could indicate suspicious activity.
  5. Severity Assessment:

    • If the access was made using a non-Helm client or across multiple namespaces, the severity is marked as "High".
    • Otherwise, it's marked as "Medium".

In essence, this query helps identify potential unauthorized access to sensitive information in a Kubernetes environment, focusing on Helm-managed secrets, and assesses the severity of such incidents based on the context of the access.