Log sources › kubernetes:apiserver
kubernetes:apiserver
Inverted view: what can be detected if this is the log you have. Containers
10
channels
9
analytics
9
techniques
4
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Pod spec with hostPath or privileged securityContext |
DC0092 Volume Modification | AN0612 | 1 |
Resource creation and update logs |
DC0028 Image Metadata | AN0986 | 1 |
authentication.k8s.io/v1beta1 |
DC0002 User Account Authentication | AN1268 | 1 |
create/exec: Kubernetes API calls to exec into containers or create pods from curl, kubectl, or SDK clients |
DC0072 Container Creation | AN0233 | 1 |
exec into pod followed by secret retrieval via API |
DC0032 Process Creation | AN0571 | 1 |
get/list requests to /api/v1/secrets or /api/v1/namespaces/*/serviceaccounts |
DC0002 User Account Authentication | AN0571 | 1 |
kubectl exec or kubelet API calls targeting running pods |
DC0032 Process Creation | AN0177 | 1 |
list or get requests against pods, deployments, or nodes |
DC0037 Pod Enumeration | AN1352 | 1 |
serviceAccount token used in API requests not tied to workload identity |
DC0007 Web Credential Usage | AN0530 | 1 |
verb=create, resource=cronjobs, group=batch |
DC0001 Scheduled Job Creation | AN0582 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location | stealth | 21 | 1 |
| T1053.007 Container Orchestration Job | execution, persistence, privilege escalation | 0 | 0 |
| T1059.013 Container CLI/API | execution | 0 | 0 |
| T1110.004 Credential Stuffing | credential access | 0 | 0 |
| T1550.001 Application Access Token | lateral movement | 4 | 0 |
| T1552.007 Container API | credential access | 4 | 0 |
| T1609 Container Administration Command | execution | 3 | 0 |
| T1611 Escape to Host | privilege escalation | 2 | 3 |
| T1613 Container and Resource Discovery | discovery | 1 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2023-26360 | Adobe ColdFusion | T1036.005 | Mapped |
| CVE-2025-22224 | VMware ESXi and Workstation | T1611 | Mapped |
| CVE-2025-22225 | VMware ESXi | T1611 | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | T1611 | Mapped |