Kubernetes Secrets Dumping via Kubectl

Rule Info

Name
Kubernetes Secrets Dumping via Kubectl
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to dump Kubernetes secrets using kubectl. Attackers with sufficient RBAC permissions may enumerate secrets cluster-wide to harvest credentials, API tokens, TLS certificates, or other sensitive data stored as Kubernetes secrets.
Date
2026-05-28 00:00:00
Modified
None
Id
f7c2e841-9b3d-4f05-a612-d8e4c07b5a93
Tags
attack.credential-access attack.t1552 attack.t1552.007
Type
Nextron Sigma feed only (private)

Rule History