Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0572 — Suspicious RoleBinding or ClusterRoleBinding Assignment in Kubernetes
DET0572

Suspicious RoleBinding or ClusterRoleBinding Assignment in Kubernetes

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1579 Analytic 1579
Containers

Detects assignment of high-privilege roles to user or service accounts via Kubernetes RoleBinding or ClusterRoleBinding objects, especially outside of CI/CD automation or from unknown IPs.

kubernetes:audit create or update events for RoleBinding or ClusterRoleBinding objects
[UserAgent] Filter expected sources of automated role assignment (e.g., CI/CD tooling)
[RoleName] Scope to privileged roles like cluster-admin, edit, admin
[TimeWindow] Detect after-hours or irregular-time assignments
[UserContext] Define known service accounts and privileged operators to reduce noise

Detected Techniques

1

Details

MITRE ID
DET0572
STIX ID
x-mitre-detection-strategy--7c27cb31-4806-479f-a07b-900450236a57
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.