Rule Info
Name
Kubernetes Events Deleted
Author
Leo Tsaousis (@laripping)
Description
Detects when events are deleted in Kubernetes.
An adversary may delete Kubernetes events in an attempt to evade detection.
Reference
Date
2024-03-26 00:00:00
Modified
None
Id
3132570d-cab2-4561-9ea6-1743644b2290
Tags
attack.t1070 DEMO
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit