Azure Arc-enabled Kubernetes Azure-Microsoft.Kubernetes

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Kubernetes rules that match the resource provider but no specific operation.NN
Microsoft.Kubernetes/connectedClusters/DeleteDeletes connectedClustersNY
Microsoft.Kubernetes/connectedClusters/listClusterUserCredential/actionList clusterUser credentialNY
Microsoft.Kubernetes/connectedClusters/listClusterUserCredentials/actionList clusterUser credential(preview)NN
Microsoft.Kubernetes/connectedClusters/WriteWrites connectedClustersNY
Microsoft.Kubernetes/locations/operationstatuses/writeWrite Operation StatusesNN
Microsoft.Kubernetes/register/actionRegisters Subscription with Microsoft.Kubernetes resource providerNN
Microsoft.Kubernetes/unregister/actionUn-Registers Subscription with Microsoft.Kubernetes resource providerNN

any: Azure Arc-enabled Kubernetes (catch-all)

#
Namespace
Microsoft.Kubernetes

Description

Catch-all for Azure-Microsoft.Kubernetes rules that match the resource provider but no specific operation.

Microsoft.Kubernetes/connectedClusters/Delete

#
Namespace
Microsoft.Kubernetes

Description

Deletes connectedClusters

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Kubernetes/connectedClusters/listClusterUserCredential/action

#
Namespace
Microsoft.Kubernetes

Description

List clusterUser credential

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Arc Cluster Credential Access by Identity from Unusual Source source medium: Detects when a service principal or user performs an Azure Arc cluster credential listing operation from a source IP not previously associated with that identity. The listClusterUserCredential action retrieves credentials for the Arc Cluster Connect proxy, enabling kubectl access through the Azure ARM API. An adversary using stolen service principal credentials will typically call this operation from infrastructure not previously seen for that SP. By tracking the combination of caller identity and source IP, this rule avoids false positives from backend services and CI/CD pipelines that rotate IPs but maintain consistent identity-to-IP patterns over time.T1078, T1078.004, T1552, T1552.007

Microsoft.Kubernetes/connectedClusters/listClusterUserCredentials/action

#
Namespace
Microsoft.Kubernetes

Description

List clusterUser credential(preview)

Microsoft.Kubernetes/connectedClusters/Write

#
Namespace
Microsoft.Kubernetes

Description

Writes connectedClusters

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Kubernetes/locations/operationstatuses/write

#
Namespace
Microsoft.Kubernetes

Description

Write Operation Statuses

Microsoft.Kubernetes/register/action

#
Namespace
Microsoft.Kubernetes

Description

Registers Subscription with Microsoft.Kubernetes resource provider

Microsoft.Kubernetes/unregister/action

#
Namespace
Microsoft.Kubernetes

Description

Un-Registers Subscription with Microsoft.Kubernetes resource provider

References #