Detection rules › Falco
K8s ClusterRoleBinding Created
Detect any attempt to create a clusterrolebinding
Telemetry coverage
| Platform | Record / event type |
|---|---|
| Kubernetes | create-clusterrolebindings: create clusterrolebindings |
Rules detecting the same action
These rules filter on the same operation.
- Attach to cluster-admin Role (Falco)
- Direct Interactive Kubernetes API Request by Unusual Utilities (Elastic)
- GKE Cluster-Admin Role Binding Created or Modified (Elastic)
- GKE Creation of a RoleBinding Referencing a ServiceAccount (Elastic)
- GKE Service Account Modified RBAC Objects (Elastic)
- Google Cloud Kubernetes RoleBinding (Sigma)
- Kubernetes Cluster-Admin Role Binding Created (Elastic)
- Kubernetes ClusterRoleBinding to Privileged Role (Panther)
Stages and Predicates
Stage 1: falco_condition
and
jevt.rawtime is_not_null
objectRef.resource eq "clusterrolebindings"
responseStatus.code starts_with "2"
stage eq "ResponseComplete"
verb eq "create"
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
jevt.rawtime | is_not_null | field:"jevt.rawtime" kind:is_not_null | |
objectRef.resource | eq |
| field:"objectRef.resource" kind:eq value:"clusterrolebindings" |
responseStatus.code | starts_with |
| field:"responseStatus.code" kind:starts_with value:"2" |
stage | in |
| field:"stage" kind:in value:"ResponseComplete" |
verb | eq |
| field:"verb" kind:eq value:"create" |