Detection rules › Falco
K8s Secret Get Successfully
Detect any attempt to get a secret. Service account tokens are excluded.
Telemetry coverage
| Platform | Record / event type |
|---|---|
| Kubernetes | get-secrets: get secrets |
Rules detecting the same action
These rules filter on the same operation.
- Azure AKS Secret get or list with Suspicious User Agent (Elastic)
- Direct Interactive Kubernetes API Request by Unusual Utilities (Elastic)
- GKE Rapid Secret GET Activity Against Multiple Objects (Elastic)
- GKE Secret Access from Node or Denied Service Account (Elastic)
- GKE Secret Access via Unusual User Agent (Elastic)
- GKE Secret get or list with Suspicious User Agent (Elastic)
- GKE Unusual Service Account Secret Access via New User Agent (Elastic)
- K8s Secret Get Unsuccessfully Tried (Falco)
Stages and Predicates
Stage 1: falco_condition
and
jevt.rawtime is_not_null
objectRef.resource eq "secrets"
responseStatus.code starts_with "2"
stage eq "ResponseComplete"
verb eq "get"
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
jevt.rawtime | is_not_null | field:"jevt.rawtime" kind:is_not_null | |
objectRef.resource | eq |
| field:"objectRef.resource" kind:eq value:"secrets" |
responseStatus.code | starts_with |
| field:"responseStatus.code" kind:starts_with value:"2" |
stage | in |
| field:"stage" kind:in value:"ResponseComplete" |
verb | eq |
| field:"verb" kind:eq value:"get" |