Telemetry coverage
| Platform | Record / event type |
|---|---|
| Kubernetes | create-deployments: create deployments |
Rules detecting the same action
These rules filter on the same operation.
- Direct Interactive Kubernetes API Request by Unusual Utilities (Elastic)
- GKE Sensitive RBAC Change Followed by Workload Modification (Elastic)
- GKE Unusual Sensitive Workload Modification (Elastic)
- Kubernetes Sensitive RBAC Change Followed by Workload Modification (Elastic)
- Unusual Kubernetes Sensitive Workload Modification (Elastic)
Stages and Predicates
Stage 1: falco_condition
and
jevt.rawtime is_not_null
objectRef.resource eq "deployments"
responseStatus.code starts_with "2"
stage eq "ResponseComplete"
verb eq "create"
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
jevt.rawtime | is_not_null | field:"jevt.rawtime" kind:is_not_null | |
objectRef.resource | eq |
| field:"objectRef.resource" kind:eq value:"deployments" |
responseStatus.code | starts_with |
| field:"responseStatus.code" kind:starts_with value:"2" |
stage | in |
| field:"stage" kind:in value:"ResponseComplete" |
verb | eq |
| field:"verb" kind:eq value:"create" |