Log sources › kubernetes:audit
kubernetes:audit
Inverted view: what can be detected if this is the log you have. Containers, Linux
11
channels
11
analytics
10
techniques
72
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Failed login |
DC0002 User Account Authentication | AN1341 | 1 |
GET or LIST requests to /var/run/secrets/kubernetes.io/serviceaccount/ followed by access to the Kubernetes API server |
DC0055 File Access | AN1423 | 1 |
Shell process (e.g., /bin/sh, /bin/bash) spawned in a container without an interactive session attached (i.e., automation anomaly) |
DC0064 Command Execution | AN0233 | 1 |
Unauthorized container creation or kubelet exec logs |
DC0088 Logon Session Metadata | AN1007 | 1 |
authentication.k8s.io |
DC0002 User Account Authentication | AN1547 | 1 |
create |
DC0019 Pod Creation DC0060 Service Creation |
AN1304 | 1 |
create or update events for RoleBinding or ClusterRoleBinding objects |
DC0010 User Account Modification | AN1579 | 1 |
create: Pod/Container created with image tag 'latest' or mutable tag; imagePullPolicy=Always; noDigest=true |
DC0072 Container Creation | AN0691 | 1 |
kubectl delete or patch of security pods/admission controllers |
DC0041 Service Metadata | AN1373 | 1 |
process execution involving curl, grep, or awk on secrets |
DC0064 Command Execution | AN0859 | 1 |
seccomp or AppArmor profile changes |
DC0041 Service Metadata | AN0889 | 0 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1059.013 Container CLI/API | execution | 0 | 0 |
| T1078 Valid Accounts | stealth, persistence, privilege escalation, initial access | 56 | 46 |
| T1098.006 Additional Container Cluster Roles | persistence, privilege escalation | 0 | 0 |
| T1110.003 Password Spraying | credential access | 0 | 0 |
| T1133 External Remote Services | persistence, initial access | 20 | 25 |
| T1204.003 Malicious Image | execution | 0 | 0 |
| T1528 Steal Application Access Token | credential access | 14 | 1 |
| T1543.005 Container Service | persistence, privilege escalation | 0 | 0 |
| T1552.001 Credentials In Files | credential access | 24 | 3 |
| T1685 Disable or Modify Tools | defense impairment | 164 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1133 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1133 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1133 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1133 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1133 T1552.001 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1078 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1078 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1133 | Mapped |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1133 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1133 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1133 | Mapped |
| CVE-2020-25506 | D-Link DNS-320 Device | T1133 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1133 | Stale |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1133 | Mapped |
| CVE-2021-1497 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-1498 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-20035 | SonicWall SMA100 Appliances | T1078 | Mapped |
| CVE-2021-22894 | Ivanti Pulse Connect Secure | T1078 | Mapped |
| CVE-2021-22899 | Ivanti Pulse Connect Secure | T1078 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1133 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1133 | Mapped |
| CVE-2021-26857 | Microsoft Exchange Server | T1133 | Mapped |
| CVE-2021-36934 | Microsoft Windows | T1078 | Mapped |
| CVE-2021-41379 | Microsoft Windows | T1078 | Mapped |
| CVE-2021-42321 | Microsoft Exchange | T1078 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1078 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1133 | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1078 | Mapped |
| CVE-2022-21919 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-22047 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-22718 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-22948 | VMware vCenter Server | T1078 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1078 | Mapped |
| CVE-2022-24521 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-26138 | Atlassian Confluence | T1552.001 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1078 | Mapped |
| CVE-2022-26904 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-37969 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-41073 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1078 | Mapped |
| CVE-2022-41125 | Microsoft Windows | T1078 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1078 | Mapped |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | T1078 | Mapped |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense | T1078 T1133 | Mapped |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | T1078 | Mapped |
| CVE-2023-20867 | VMware Tools | T1078 | Mapped |
| CVE-2023-21674 | Microsoft Windows | T1078 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1078 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1078 | Stale |
| CVE-2023-23397 | Microsoft Office | T1078 | Mapped |
| CVE-2023-27524 | Apache Superset | T1078 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1133 | Mapped |
| CVE-2023-28229 | Microsoft Windows CNG Key Isolation Service | T1078 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1078 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1078 T1133 | Mapped |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security | T1078 | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | T1078 | Mapped |
| CVE-2023-48365 | Qlik Sense | T1133 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1133 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1078 | Mapped |
| CVE-2024-20399 | Cisco NX-OS | T1078 | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | T1078 | Mapped |
| CVE-2024-37085 | VMware ESXi | T1078 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1528 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1133 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1078 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1552.001 | Mapped |
| CVE-2024-57968 | Advantive VeraCore | T1078 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1078 | Mapped |
| CVE-2025-31161 | CrushFTP CrushFTP | T1078 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1133 | Mapped |