Kubernetes Events Deleted

Rule Info

Name
Kubernetes Events Deleted
Author
Leo Tsaousis (@laripping)
Description
Detects when events are deleted in Kubernetes. An adversary may delete Kubernetes events in an attempt to evade detection.
Date
2024-03-26 00:00:00
Modified
None
Id
3132570d-cab2-4561-9ea6-1743644b2290
Tags
attack.t1070 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Leo Tsaousis
Merge PR #4694 from @LAripping - Add native Kubernetes detections
2024-03-26