GCP Break-glass Container Workload Deployed

 Original Source: [Sigma source]
Title: GCP Break-glass Container Workload Deployed
Status: test
Description:Detects the deployment of workloads that are deployed by using the break-glass flag to override Binary Authorization controls.
References:
  -https://cloud.google.com/binary-authorization
Author: Bryan Lim
Date: 2024-01-12
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548'
Logsource:
  • product: gcp
  • service: gcp.audit
Detection:
  selection:
    data.protoPayload.resource.type: 'k8s_cluster'
    data.protoPayload.logName:
      -'cloudaudit.googleapis.com/activity'
      -'cloudaudit.googleapis.com%2Factivity'

    data.protoPayload.methodName: 'io.k8s.core.v1.pods.create'
  keywords:
    - 'image-policy.k8s.io/break-glass'
  condition:selection and keywords
Falsepositives:
  -Unknown
Level: medium